If you don't mind me asking, how was the order placed, online or on the phone ?
Ask the company if they are PCI compliant, if there not they should be and if they are and this happened something is very wrong.
https://www.pcisecuritystandards.org/...