eJuice Direct
bd_531f94f6c0bf760f · schema v1 · pii pii-v1
Full breach record for eJuice Direct →eJuice Direct disclosed a cybersecurity incident where a malicious script was injected into its e-commerce website, potentially allowing unauthorized access to customer payment card details (card number, CVC/CVV, expiration date) between August 15, 2020, and July 7, 2021. The company engaged a forensic firm, removed the script, and implemented MFA and a Web Application Firewall. Approximately 21 Rhode Island residents were explicitly noted as impacted.
J jump to incidentP pin to compareR raw source
Incident timeline
Aug 15, 2020
Begins
Jul 16, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Indiana State AGbd_ea017abef3b399802021-07-16Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.