International Vapor Group (IVG) notified customers of a security incident affecting directvapor.com and vaprofi.com. Between January 19, 2018, and June 30, 2018, an unauthorized individual accessed the e-commerce site and inserted malicious code to capture credit/debit card information, names, and addresses. IVG engaged forensic investigators, upgraded hardware, changed software processes, implemented monitoring, and migrated servers to AWS. Customers were advised to monitor bank statements.