HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTPIILowContained
Ejuice Store
bd_531f94f6c0bf760f · schema v1 · pii pii-v1
Full breach record for Ejuice Store →eJuice Direct experienced a cybersecurity incident involving its e-commerce website where a malicious script was injected by an unauthorized third party. The breach occurred between August 15, 2020, and July 7, 2021, potentially exposing payment card details (card number, CVC/CVV, expiration date). The company engaged a forensic firm, removed the script, and implemented MFA and a Web Application Firewall.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542992
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 16, 2021
- Raw hash
- 3ed411a75eec08e2cc4802da5ed566952249c150740d21b4bc12c25926c68897
Reporting entity
- Name
- Ejuice Storenorm: ejuice store
- Domain
- ejuicestore.com
Victim entity
- Name
- Ejuice Storenorm: ejuice store
- Domain
- ejuicestore.com
Incident
- Discovered
- Jul 7, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.