The International Council of Shopping Centers (ICSC) disclosed a security incident involving unauthorized code injected into the checkout page of www.icsc.org. The malicious code was active from March 24, 2017, to August 18, 2017, potentially capturing payment card information, names, addresses, and CVVs. ICSC removed the code, engaged forensic experts, and notified payment card networks. The breach affects members and customers who entered payment data during the specified period.