IM Shopping, Inc. reported a data breach affecting its Gift Card Mall website. An unauthorized script was injected into the site code between April 24, 2019, and discovered on May 21, 2019. The script exfiltrated consumer name, address, and payment card details (including CVV) to an external site. IM Shopping engaged a cybersecurity firm, removed the script, and logged out affected users. They provided 24 months of credit monitoring and identity protection services to affected individuals.