Data breach
CafePress
- Records
- 23,579,964
- Breach date
- 19 February 2019Estimated
- Added
- 1 December 2024
What was exposed
5 types of data · 3 more reported · 1 puts you at serious risk
- Email addresses23,579,925
- Passwords21,374,876
- Names757,226
- Home addresses689,151
- Phone numbers511,717
- Social security numbersReported, not counted
- Government IDsReported, not counted
- Security questionsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In February 2019, an unidentified attacker exploited a SQL injection vulnerability in CafePress, the online marketplace for customized t-shirts, mugs, and other merchandise, and gained access to a database holding customer records. The indexed dataset from this breach contains roughly 23.6 million rows, including about 21.4 million passwords and more than 23.5 million email addresses. The company did not alert customers until September 2019, months after a security researcher had warned it about the flaw, and the episode later drew an enforcement action from the Federal Trade Commission.
Breach Timeline
February 19, 2019: An attacker obtained customer information from a CafePress database without authorization, according to the company's later notification and a multistate attorney general settlement document.
March 13, 2019: A third-party security researcher notified CafePress of a SQL injection vulnerability and demonstrated that customer records could be extracted.
April 4, 2019: CafePress forced a password reset on all customer accounts, presenting it as a policy update rather than a breach warning.
August 2019: Independent researchers reported that tens of millions of CafePress user records were circulating in hacking circles.
September 2019: CafePress publicly acknowledged the breach and began emailing affected customers.
March 15, 2022: The FTC announced a proposed settlement with CafePress's former owner, Residual Pumpkin Entity, LLC, and current owner, PlanetArt, LLC, including a $500,000 payment for redress.
June 24, 2022: The FTC finalized the orders, requiring a comprehensive information security program and 20 years of independent security assessments.
What Information Was Compromised?
Our analysis found the following data types in this breach: 23,579,925 email addresses, 21,374,876 passwords, 757,226 names, 689,151 home addresses, and 511,717 phone numbers.
Separately, the FTC's complaint and a settlement document filed by attorneys general from seven states describe additional data in the breach, including security questions and answers, partial payment card numbers with expiration dates, and more than 180,000 unencrypted Social Security or tax identification numbers collected from sellers. The FTC also alleged that passwords were protected with weak encryption and that some stolen records later surfaced for sale on the dark web.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Exposed passwords can be tested against other websites where users reused the same credentials, a practice known as credential stuffing. Email addresses and phone numbers are useful for targeted phishing, in which scammers pose as CafePress or other trusted companies to extract more information. Because names, addresses, and in some cases Social Security numbers were exposed, affected individuals also face an elevated risk of identity theft and fraudulent account openings. The FTC noted that some of the stolen information was found for sale on the dark web, meaning misuse is not hypothetical.
What Is CafePress Doing in Response?
CafePress reset customer passwords in April 2019 but did not confirm the breach publicly until September 2019, after independent reporting. In 2022, the FTC resolved its complaint against Residual Pumpkin Entity, LLC, the company's former owner, and PlanetArt, LLC, which bought CafePress in 2020. Under the finalized order, Residual Pumpkin paid $500,000 in redress, PlanetArt was required to notify affected consumers, and both companies must maintain a comprehensive information security program with multi-factor authentication, encrypted Social Security numbers, data minimization, and independent security assessments reported to the FTC for 20 years.
What Should You Do If You Were Affected?
Change your CafePress password, and change it anywhere else you reused it.
Watch for phishing emails referencing CafePress or your shopping history; verify links before clicking.
Check your credit reports for accounts you do not recognize. CafePress's notification offered links to Experian, Equifax, and TransUnion.
Consider a credit freeze or fraud alert if your address or Social Security number was involved, particularly if you sold items on the platform.
Be cautious with any unsolicited calls or messages that cite your personal details as proof of legitimacy.
In the news
- FTC press release, March 15, 2022ftc.gov (opens in a new tab)
- FTC press release, June 24, 2022ftc.gov (opens in a new tab)
- The Register, September 23, 2019theregister.com (opens in a new tab)
- Assurance of Voluntary Compliance with state attorneys generalag.ny.gov (opens in a new tab)
- ZDNet coverage of the FTC settlementzdnet.com
