← Cvent

2019 Third-party extension breach — payment card data

2019 Unknown records affected Share on X

Data compromised

Credit card numbers, expiration dates, billing information

Technical writeup

Malicious code was inserted into a third-party extension on Cvent's event registration page between April 16 and May 30, 2019. Potentially exposed: name, card number, expiration date, billing info. Registrants using Internet Explorer were not affected. Cvent offered one-year identity theft monitoring.

Root cause

Compromised third-party extension; supply chain attack.

References