eJuice Direct experienced a cybersecurity incident involving its e-commerce website where a malicious script was injected by an unauthorized third party. The breach occurred between August 15, 2020, and July 7, 2021, potentially exposing payment card details (card number, CVC/CVV, expiration date). The company engaged a forensic firm, removed the script, and implemented MFA and a Web Application Firewall.