Virgo Gems, LLC began sending data breach notices on October 1, 2026. The company says unauthorized code on its website may have captured payment card details from certain purchases made between August 4 and September 21, 2026.
Virgo Gems’s Data Breach Investigation
Virgo Gems, LLC sells to customers through a website that accepts online payment card transactions. In a notice dated October 1, 2026 and filed with the Massachusetts Attorney General’s office, the company told customers that it detected suspicious activity on its website on September 21, 2026. It says it started an investigation right away and brought in independent specialists to help.
According to the notice, the investigation concluded that payment card information from certain transactions made between August 4 and September 21, 2026 may have been acquired without authorization. That is a window of roughly seven weeks. The company says that on September 23, 2026 it determined that the payment card information of the person receiving the letter was affected. The notice does not say how many customers received a letter, and no public count has been published so far.
The company reports that its specialists located unauthorized code on the website and removed it. Unauthorized code on a checkout page is a well-known way for criminals to collect card details, because the code can copy what a shopper types as the purchase is entered, before the order is even processed. This kind of attack is often called web skimming, and it can run quietly for weeks because shoppers and merchants see nothing unusual on screen. The company’s notice does not use that term, and it does not say how the code got onto the site.
Virgo Gems says it shut down online transactions entirely when it found the problem. It then added several protections: every visitor now passes through a screening layer before reaching the site, the site sits behind firewalls at both the network and application level, the ability to add or change files on the website has been locked, and expert-monitored oversight is in place to catch unusual activity. The company also told the payment card brands so they could take their own steps, and it reported the incident to the Federal Bureau of Investigation.
The company retained IDX, an identity protection provider, to send the notice. The letter encourages recipients to review their card statements for anything unfamiliar and to consider asking their bank for a replacement card, which the company describes as the single most effective step a customer can take. The notice does not describe offering credit monitoring or identity protection services to affected customers.
The period between the first affected purchase and the date the problem was found matters. A customer who bought something from the site at any point between early August and late September 2026 and paid by card could have had card details copied. The notice says only certain transactions were affected, so receiving a letter is the clearest sign that a specific person’s card was among them. People who did not receive a letter but remember a purchase during that window may still want to watch their statements closely.
Card data stolen this way is frequently sold in bulk on criminal marketplaces and then tested with small charges to see which cards still work. Those small test charges, often just a dollar or two, are easy to miss. Fraud can also show up weeks or months after the theft, once the stolen numbers have been resold, so vigilance should not stop after the first few days.
The notice does not say whether the affected cards were debit or credit cards, whether any customer has reported fraud, or whether other categories of information such as billing addresses, email addresses or phone numbers were also exposed. Only the name, card number, expiration date and security code are listed. We will update this page if the company or a regulator publishes more detail, including the number of people affected.
Payment card breaches differ from many other data breaches in one useful way. Card numbers can be cancelled and replaced quickly, unlike a Social Security number, so a fast response by the cardholder can shut off most of the risk. That is why the steps below focus on checking statements, contacting the card issuer and watching for fraud over the coming months.
When Did This Breach Occur?
Virgo Gems says it detected suspicious activity on its website on September 21, 2026. It reports that payment card information from certain transactions between August 4 and September 21, 2026 may have been acquired without authorization, and that it determined on September 23, 2026 that affected customers’ card information was involved. Notices are dated October 1, 2026.
What Information Was Breached?
The company says the information may have included the customer’s first and last name, payment card number, card expiration date and card security code. The notice does not list any other categories, such as Social Security numbers or addresses.
What You Can Do
If you received a notice from Virgo Gems, consider these steps:
- Review your card statements closely, including small charges you do not recognize, and report anything suspicious to your bank or card issuer right away.
- Ask your card issuer whether you should get a replacement card, since the card number, expiration date and security code may all have been exposed.
- Turn on transaction alerts with your bank so you hear about charges as they happen.
- Check your credit reports for free at annualcreditreport.com, and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Report suspected fraud or identity theft to the Federal Trade Commission, local law enforcement and your state Attorney General.
File a Data Breach Lawsuit Against Virgo Gems
If you received a notice that your payment card information may have been involved in the Virgo Gems data breach, or you made a card purchase on the company’s website between August and September 2026, you may be entitled to compensation. Businesses that take card payments online are expected to keep those systems secure, and people whose card data is exposed can face fraud, time lost dealing with their bank, and ongoing worry about misuse.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.