eJuice Direct
ent_c1462b066c798b58e3280c5d
Disclosures
2
State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
47,764
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- eJuice Direct
- Normalized
- ejuice direct— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ejuicedirect.com
Disclosure history (2)newest first
- California State AGas victim2021-07-16
eJuice Direct disclosed a cybersecurity incident where a malicious script was injected into its e-commerce website, potentially allowing unauthorized access to customer payment card details (card number, CVC/CVV, expiration date) between August 15, 2020, and July 7, 2021. The company engaged a forensic firm, removed the script, and implemented MFA and a Web Application Firewall. Approximately 21 Rhode Island residents were explicitly noted as impacted.
- Indiana State AGas victim2021-07-16
eJuice Direct reported a data breach to the Indiana Attorney General. The breach occurred on 2020-08-15 and was reported on 2021-07-16. 1,690 Indiana residents were affected. 47,764 individuals affected in total.