HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Southbeachsmoke.com; vaporfi.com; directvapor.com
bd_8f38d14e2f2583f9 · schema v1 · pii pii-v1
Full breach record for Southbeachsmoke.com; vaporfi.com; directvapor.com →California AG SB24 breach notification for Southbeachsmoke.com, directvapor.com, and vaporfi.com. Unauthorized access to online checkout pages between Sept 14-23, 2020. Exposed names, addresses, and credit/debit card details (including CVV). Investigation completed Oct 13, 2020. Remediation included fixing vulnerabilities, system audits, and implementing MFA for remote access.
California clockDiscovered Sep 23, 2020 → Notified Dec 16, 202084d ✗ CA 60-day late13 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_7cc095a20dc998dfMaine State AGfiled 2020-12-21Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197405
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 21, 2020
- Raw hash
- 64e70610dc85ce106aa57fc3bf02d9e6e2fbbd2a690c1c6cea07e5feb78b3b84
Reporting entity
- Name
- Southbeachsmoke.com; vaporfi.com; directvapor.comnorm: southbeachsmokecom vaporficom directvaporcom
Victim entity
- Name
- Southbeachsmoke.com; vaporfi.com; directvapor.comnorm: southbeachsmokecom vaporficom directvaporcom
Incident
- Discovered
- Sep 23, 2020
- Materiality determined
- —
- Notification sent
- Dec 16, 2020
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 13 weeks(89 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 23, 2020→ Notified: Dec 16, 202084d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.