Several credit cards that appear to belong to customers of Bebe Storesin the United States were discovered on an underground website that allows transactions in stolen goods and data.
The information has been confirmed by various financial institutions, who purchased some cards and checked them against a common merchant they had in order to determine how the incident occurred.
Since Bebe Stores was the store they all had in common, we can assume that's where the hackers struck. The electronic payment system doesn't seem to have been affected by the incident, because the hackers were selling the information on the card's magnetic stripe through the machine the card is swiped at in the store.
There has been no official response from Bebe Stores yet. The chain has over 200 stores, but there is still no information on where the attack took place.
The financial institutions purchased these cards from a underground page that advertised them under the title “Happy Winter Update.” The price for each card ranged from $10 to $27.
It was discovered, after analyzing the transactions, that the cards had been used at Bebe Stores, between November 18 and November 28. In a similar attack earlier in 2014 at “Home Depot”, 56 million cards were stolen, costing the banks $43 million.

