International Vapor Group
bd_9bfda876719a0ec5 · schema v1 · pii pii-v1
Full breach record for International Vapor Group →International Vapor Group, Inc. notified the NH AG of a security incident where an unauthorized individual inserted malicious code into its e-commerce sites (vaporfi.com, directvapor.com) between Jan 19, 2018 and Jun 30, 2018. This occasionally captured payment card info. 48 NH residents were notified on March 12, 2019. IVG upgraded hardware, moved to AWS, and implemented new monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 19, 2018
Begins
Mar 1, 2019
Discovered
Mar 18, 2019
Filed
vs. sector median
5 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_32ea1fe06515f3f22019-03-18Verified
- California State AGbd_8c8ab79255b614652019-03-12 · +6dCandidate
- Montana State AGbd_ae81a64fb5f14eac2019-03-12 · +6dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Mar 12 (CA), last Mar 18 (NH) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.