Net32, Inc. disclosed that a third-party vendor misused its log-in credentials to improperly access Net32's order management system between September 22 and September 25, 2018. The vendor used these credentials to generate anomalous order activity, revealing credit card information. Net32 suspended the vendor's credentials on September 25 and required all vendors to reset passwords. Personal information, potentially including credit card numbers, may have been exposed. Net32 offered free credit monitoring via Experian to affected customers.