Those details suggest that either 1) the original company you purchased from isn’t legit; 2) that company has a crooked employee selling that transaction to scammers or is part of the scammer gang; 3) that company got hacked and all the info you listed was stolen from their server; or 4) the company you purchased from is using a third party firm to process their transactions and THAT transaction firm has problems 1 to 3. So, you see, there are many ways they could obtain those transaction details and them having that info does not make them legit.
Related story: My VERY FIRST e-commerce transaction in the early 90s got hacked. I was at a trade show in Atlanta and, when I returned to my hotel room, there was a message asking me to call my credit card company. My card had been cancelled because the entire database of transactions for Networld/Interop had been stolen and the thieves were making fraudulent charges to the stolen card numbers. Security is obviously much improved since then, but some merchants still keep all transaction info on their servers or the companies they hire to process their transactions keep the info.
I suspect it was #3 in your list. But everything is intact as of now. I’ve changed my user ID, password and all monies that were in my bank accounts are still there today. I’ve also put holds on the two cards they had the last 4 digits to and both accounts are sending me new cards and they’ve verified no new transactions have occurred in the last two weeks. Bank and LifeLock have been notified so I’m feeling pretty confident at this point.