BookShark LLC reported a data breach involving unauthorized code injected into its website (bookshark.com) between March 11, 2019, and August 26, 2019. The code captured customer login credentials and payment card details (including CVV). BookShark engaged a cybersecurity firm, removed the code, reset passwords, and notified affected California residents via statutory breach notices.