Holder said that sites like these are not necessarily phishing sites, but that at some point they sold their data to another entity and that it eventually made its way into criminal hands.
However this provision is open to interpretation and may be understood to apply only to an entity which outsources the data processing in the first instance.