National retail chain BrightMart has confirmed that point-of-sale systems at approximately 800 locations were compromised by malware between February 12 and March 30, 2026. Customer payment card data including card numbers, expiration dates, and CVV codes may have been stolen during in-store transactions.

The company discovered the breach after payment card networks flagged a pattern of fraudulent transactions linked to customers who had recently shopped at BrightMart stores. An investigation revealed that attackers gained access through a compromised third-party vendor that manages the retailer's POS software updates.