The Organization received a report of unusual card activity from its credit card processor. The Organization investigated, and determined that a vulnerability existed on its website that would permit access to certain customer payment card information if the vulnerability was exploited. On or around May 24, 2019, the investigation determined that there was evidence that the vulnerability was exploited and that there was unauthorized access to payment card information.

