HackingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCILow
Southbeachsmoke.com; vaporfi.com; directvapor.com
bd_7cc095a20dc998df · schema v1 · pii pii-v1
Full breach record for Southbeachsmoke.com; vaporfi.com; directvapor.com →Three e-commerce websites, Southbeachsmoke.com, vaporfi.com, and directvapor.com, reported an unauthorized access incident that occurred on September 14, 2020. The breach was discovered on September 23, 2020. The compromised information includes customers' names in combination with their financial account or credit/debit card numbers and associated security codes or PINs. A total of 10,544 individuals were affected, including 3 residents of Maine, who were notified in writing on December 21, 2020.
Maine clockDiscovered Sep 23, 2020 → Filed with AG Dec 21, 202089d ⏱ ME AG >30d13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8f38d14e2f2583f9California State AGfiled 2020-12-21Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/f3da90ac-5ebb-440c-a6f7-0b611f8637d0.shtml
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 21, 2020
- Raw hash
- fbad15b0609ccd8dfa606c579eafe79ebf5e05a8b03fe6fc23e3a11c43065eeb
Reporting entity
- Name
- Southbeachsmoke.com; vaporfi.com; directvapor.comnorm: southbeachsmokecom vaporficom directvaporcom
Victim entity
- Name
- Southbeachsmoke.com; vaporfi.com; directvapor.comnorm: southbeachsmokecom vaporficom directvaporcom
Incident
- Discovered
- Sep 23, 2020
- Materiality determined
- —
- Notification sent
- Dec 21, 2020
- Affected individuals
- 3
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSPCI
- Attack vector
- Unauthorized Access
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- ME AG >30d · 89dME resident >60d · 89d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Sep 23, 2020→ Filed with AG: Dec 21, 202089d 30 days (soft) ME AG >30d Maine Discovered: Sep 23, 2020→ Notified: Dec 21, 202089d 60 days (analyst band; statutory cap is 30 days) ME resident >60d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.