International Vapor Group
bd_8c8ab79255b61465 · schema v1 · pii pii-v1
Full breach record for International Vapor Group →International Vapor Group (IVG) notified customers of a security incident affecting its e-commerce sites (directvapor.com, vaprofi.com) between January 19, 2018, and June 30, 2018. An unauthorized individual inserted malicious code into the websites, capturing credit/debit card information (name, address, card number, expiration date, CVV) for online purchases. Phone and retail store transactions were not affected. IVG engaged forensic investigators, upgraded hardware, modified software processes, implemented new monitoring, and migrated servers to AWS. No specific count of affected individuals was disclosed.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 19, 2018
Begins
Mar 12, 2019
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_ae81a64fb5f14eac2019-03-12Verified
- Massachusetts State AGbd_32ea1fe06515f3f22019-03-18 · +6dVerified
- New Hampshire State AGbd_9bfda876719a0ec52019-03-18 · +6dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Mar 12 (MT), last Mar 18 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.