Okay, slight update. These herbs just now responded to my email. I told them in the email about how I didn't make changes on such and such date and time and the $3.5k in attempted charges and how one got through and I went ahead and contacted my bank and changed my password/email. Their reply? Hey sorry for the delay, we deleted all your billing info, change your password.
Lmaoo no mention of the charge, no mention of the shoe they shipped to me, no sorry we got you account compromised, no contact us to discuss the refund (good thing my bank already gave it to me). And they had the audacity to send a follow up email just TEN MINUTES LATER asking how was the customer service....My guy...So i guess to them this case is concluded? Fine by me. Guess I'm keeping the shoe. I'll keep it DS for while, not sure how long tho, just incase. I was 100% willing to send them back on their cost, but guess homie closed the case.
On the bright side the last sentence did mention they are looking into multi factor authentication - though I'm positive they've been saying this since the summer (which keep in mind, they've been breached well before August, and were aware of the "big public" breach before they made it public). Long as my payment info is gone.