Cyber Incident Victim: Element Vape
Date:
Feb 2022
Location:
United States of America
Summary
A prominent online e-cigarette retailer experienced a compromise resulting in credit card skimming malware being deployed on its live website. The malicious script, hosted externally and heavily obfuscated, harvested payment details and customer information before exfiltrating the data via a Telegram bot. The infection occurred after the retailer's site was confirmed clean in early February and remained active until removed following external disclosure. This incident follows a prior data breach years earlier that led to legal action. The company, operating across the U.S. and Canada, resolved the compromise promptly after notification but provided limited public details about the attack vector or backend infiltration method.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Element Vape, a major online retailer of e-cigarettes, vaping devices, and related products operating in the U.S. and Canada, experienced a cybersecurity incident involving unauthorized credit card skimming code on its live website. Security researchers at BleepingComputer confirmed the presence of malicious JavaScript designed to harvest payment information from customers during checkout. Analysis of historical site snapshots indicated the skimmer was not present on ElementVape.com as of February 5, 2022, or earlier, suggesting the compromise occurred sometime between that date and February 18, 2022, when the investigation was published. The attack involved injecting six lines of code that loaded a malicious third-party JavaScript file (//weicowire[.]com/js/jquery/frontend.js) containing heavily obfuscated payloads. This script remained active on the production site until the day of disclosure, enabling the theft of sensitive customer data during online transactions.

The malicious JavaScript collected payment card details, email addresses, and physical addresses before exfiltrating the stolen information via a hardcoded Telegram bot API. The payload incorporated anti-reverse-engineering techniques to hinder analysis. While the exact method of initial compromise remains undetermined, this incident followed a previous 2018 data breach at Element Vape that exposed customer information and resulted in a 2019 class-action lawsuit. Upon notification by BleepingComputer through Zendesk support channels on February 18, Element Vape removed the skimming code the same day. Customers were advised to monitor their payment card statements for fraudulent activity due to potential data exposure. The company, which has operated since 2013 and expanded services through a 2021 partnership with PUDO Inc. for Canadian pickup locations, had not publicly disclosed technical details about the attack's scope or intrusion vectors at the time of reporting.
