Is customer data safe, and do I need to disclose a breach?
If a Magecart skimmer or database compromise exposed customer or payment data, you may have legal disclosure obligations under GDPR, PCI-DSS or state breach-notification laws, and your payment processor may need to be notified. During cleanup we determine what data was likely exposed and for how long, and we preserve the forensic evidence you’d need. We’re not lawyers, so we won’t give legal advice, but we’ll give you a clear technical breach summary so you and your counsel can decide what to disclose.