International Vapor Group
ent_69532f32a2d7186b9c2c425c
Disclosures
4
State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
211
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- International Vapor Group
- Normalized
- international vapor— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- Massachusetts State AGas victim2019-03-18
International Vapor Group reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-18. 211 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2019-03-18
International Vapor Group, Inc. notified the NH AG of a security incident where an unauthorized individual inserted malicious code into its e-commerce sites (vaporfi.com, directvapor.com) between Jan 19, 2018 and Jun 30, 2018. This occasionally captured payment card info. 48 NH residents were notified on March 12, 2019. IVG upgraded hardware, moved to AWS, and implemented new monitoring.
- California State AGas victim2019-03-12
International Vapor Group (IVG) notified customers of a security incident affecting its e-commerce sites (directvapor.com, vaprofi.com) between January 19, 2018, and June 30, 2018. An unauthorized individual inserted malicious code into the websites, capturing credit/debit card information (name, address, card number, expiration date, CVV) for online purchases. Phone and retail store transactions were not affected. IVG engaged forensic investigators, upgraded hardware, modified software processes, implemented new monitoring, and migrated servers to AWS. No specific count of affected individuals was disclosed.
- Montana State AGas victim2019-03-12
International Vapor Group notified affected individuals in March 2019 that unauthorized access to its e-commerce sites (directvapor.com, vaprofi.com) between Jan 19 and Jun 30, 2018 compromised customer PII and payment card data. Malicious code was inserted to capture card info. IVG engaged forensic investigators and enhanced security infrastructure.