Menu
Browse

My Freedom Smokes

Primary URL Location Industry
myfreedomsmokes[.]com
Country United States of America
Retail Icon
Retail
Profile

My Freedom Smokes operates as an online retailer specializing in electronic cigarettes and related vaping products. The company is headquartered in the United States and serves customers across the country through its e‑commerce website. Its product catalog includes a variety of e‑cigarette devices, flavored e‑liquids, coils, batteries, and accessory items. Customers browse the site, select items, and complete purchases by submitting personal and payment information. The business model relies on direct‑to‑consumer sales via the internet rather than physical storefronts.

As an e‑commerce platform, My Freedom Smokes processes a steady flow of online orders that require the collection of names, addresses, email addresses, telephone numbers, and payment card details. The website’s order processing system is designed to transmit this data securely to payment gateways for transaction authorization. While the company does not disclose specific figures for annual sales or customer count, its operational focus is on the domestic United States market. The retailer emphasizes convenience and product variety as key aspects of its service offering to adult consumers of vaping products. All transactions are conducted in US dollars, reflecting the firm’s primary market and currency of operation.

In February 2015, malicious code was injected into the My Freedom Smokes website, potentially capturing the personal and payment data submitted during online orders. The compromised information included names, addresses, email addresses, telephone numbers, payment card numbers, expiration dates, and CVV codes. Upon discovery, the retailer removed the unauthorized code, engaged a third‑party security specialist to investigate, and implemented security enhancements to the site. Changes were also made to the order processing system to reduce the risk of similar intrusions, although the company noted that only partial card numbers were retained and CVV values were not stored. Some customers reported fraudulent financial activity during the breach period, though a definitive attribution to the incident was not established. The firm advised affected individuals to monitor their bank statements closely but did not offer identity protection or credit monitoring services. The episode highlighted the retailer’s reliance on external expertise for incident response and prompted ongoing efforts to strengthen its cybersecurity posture.

Incidents
Linked incidents available to members
1 incident