Slim CD breach exposed card data for about 1.7 million people
- Organization
- Slim CD, Inc.
- Exploit
- Hacking
- Industry
- Payment Processing
Slim CD, a Coral Springs, Florida payment gateway provider that processes card transactions for merchants in the United States and Canada, notified roughly 1.7 million people in September 2024 that their credit card details had been exposed.
The company said it detected suspicious activity on its systems on June 15, 2024. The forensic investigation that followed found the unauthorized party had first reached the network much earlier. SecurityWeek reported the initial access date as August 17, 2023, while The Record described it as as early as August 2023. Despite that dwell time of roughly ten months, Slim CD said the intruder was only in a position to view card data during a short window on June 14 and 15, 2024.
The information involved included names, addresses, credit card numbers and card expiration dates. Card verification values were not among the exposed fields. A filing with the Maine Attorney General's Office put the exact total at 1,693,000 individuals.
Slim CD said it notified law enforcement, engaged an outside security specialist and reviewed its policies and safeguards to prevent a repeat. It said it had no evidence the information had been used to commit identity theft or fraud. Slim CD's notification letter, dated September 9, 2024, offered affected individuals complimentary credit and CyberScan monitoring, a $1,000,000 insurance reimbursement policy and fully managed identity theft recovery through IDX, with an enrollment deadline of December 6, 2024. It also advised them to monitor their account statements and free credit reports.