Vera Bradley Company, a U.S. handbag manufacturer and retailer, today announced a breach of its card payment processing system, in which the card details of some of the store's customers were exposed.
According to a statement posted on the company's website, Vera Bradley says authorities had approached the company last month and informed them of a possible intrusion.
After investigating a tip from authorities with the help of a cybersecurity firm, the two concluded that a hacker (or group) had gained access to Vera Bradley's payment processing system and installed PoS malware.
The malware allowed the attacker to collect data from Vera Bradley customers. The company said only customers who had shopped at the retail store itself were affected, not those who used the online store.
“The program was specifically designed to find tracking data on the payment card magnetic stripe that may contain the card number, cardholder name, expiration date and internal verification code as the data is routed through the affected payment systems,” the company said. “There is no indication that any other customer information was compromised.”
According to the research, the PoS malware was active between July 25, 2016, and September 23, 2016, and not all payment cards used in stores during that period were recorded or filtered by the attacker.
Vera Bradley said the infection has been removed from its systems. This is a positive case of PoS malware, which was removed two months after the initial infection.
The Hutton Hotel, in Nashville, Tennessee, revealed in early September that its POS system had been infected with malware for over four years before its engineers discovered the infection and removed it.
Vera Bradley customers who believe they may have been affected and have potentially identified suspicious financial activity should read the company's announcement and learn ways to protect themselves from fraudulent transactions.

