Tempur-Pedic experienced a data breach involving its former web hosting vendor. An unauthorized individual gained access to the website servers and installed malware to capture payment card information from transactions made between January and September 2016. Affected data included names, addresses, emails, phone numbers, and payment card details. The vendor engaged forensic investigators, removed the malware, and reported the incident to federal law enforcement. One year of complimentary identity protection services was offered to affected individuals.