Outdoor Smart! Inc, which runs the Campfire Collective online store, has notified customers that unauthorized code was planted on its website to capture payment card details entered during checkout. The company says it discovered unusual activity on November 3, 2025, launched an investigation with outside cybersecurity specialists, and found that this unauthorized code may have been capturing card data going back to February 15, 2024. The code was removed on November 4, 2025, and the company confirmed on December 4, 2025 that specific customers’ information had likely been affected. This type of incident, where malicious code is quietly inserted into a checkout page to skim card numbers as customers type them in, falls under what’s generally described as a hacking or system intrusion.
The letter is addressed to individuals who made purchases on the Campfire Collective website during the roughly 21-month window the unauthorized code was active. Outdoor Smart! Inc has not stated in this filing how many people total were notified.
What information was exposed?
- Full name
- Payment card type
- Payment card number
- Card expiration date
- Card verification code (CVC)
Outdoor Smart! Inc is offering 24 months of complimentary credit monitoring and identity restoration services through Epiq’s Privacy Solutions ID product. To enroll, visit www.privacysolutionsid.com and click ‘Activate Account,’ then enter the activation code from your personal letter and complete the enrollment form and identity verification; the company notes it cannot enroll you automatically. If you have questions about enrollment, call 866-675-2006, Monday through Friday, 9:00 a.m. to 5:30 p.m. ET.
Because full card numbers, expiration dates, and CVC codes were involved, this is the kind of exposure that can lead directly to fraudulent charges, so it’s worth taking a few concrete steps now.
What should you do now?
- Contact your card issuer to ask whether the affected card should be canceled and reissued, especially since the full card number, expiration date, and CVC were exposed.
- Review recent and upcoming statements on that card closely for any charges you don’t recognize, and dispute them immediately with your bank.
- Enroll in the free 24-month Epiq Privacy Solutions ID monitoring offer described above, since it includes dark web monitoring and identity theft insurance in addition to credit monitoring.
- Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion, which is free under federal law and makes it harder for someone to open new accounts in your name.
- Pull your free credit reports at annualcreditreport.com and check them for accounts or inquiries you don’t recognize.
- For ongoing peace of mind, consider signing up for a service like Aura or LifeLock, which can alert you if your card details or other personal information turn up elsewhere.
- Watch for phishing emails or calls that reference this breach, since scammers sometimes use real incidents to trick people into handing over more information.
If you have questions, Outdoor Smart! Inc can be reached at 888-367-0556 (Monday through Friday, 9:00 a.m. to 9:00 p.m. ET) or by writing to Unit 2, 890 Taylor Creek Drive, Ottawa, Ontario K4A 0Z9.