A data breach last year at California-based customer support service [24]7.ai may have exposed the credit card information of customers of Sears, Kmart and Atlanta-based Delta. These organizations are now faced with the task of sorting through potential liability stemming from state data breach notification laws and the role of third-party vendors in data exposure.

In a press statement issued on April 4, Delta announced that it had been made aware of the breach on March 28 and had begun working with [24]7.ai to get a sense of the breach’s scope and impact. Delta also reportedly contacted federal law enforcement and forensic teams to confirm the breach and has launched a website to answer consumer questions about the breach.