[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3jzaijfayzow1":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda4882512f","CafePress","CafePress Data Breach","cafepress","cafepress.com","2019-02-20T00:00:00.000Z","2019-08-05T01:18:43.000Z","2019-08-05T20:02:32.000Z","2026-07-19T16:25:13.271Z","Verified custom merchandise retailer data breach","https:\u002F\u002Fwww.ftc.gov\u002Fnews-events\u002Fnews\u002Fpress-releases\u002F2022\u002F03\u002Fftc-takes-action-against-cafepress-data-breach-cover",[16,18,19,20,21],"https:\u002F\u002Fwww.ftc.gov\u002Fsystem\u002Ffiles\u002Fftc_gov\u002Fpdf\u002FCafePress-Complaint_0.pdf","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcafepress-data-breach-exposes-personal-info-of-23-million-users\u002F","https:\u002F\u002Fgrahamcluley.com\u002Fcafepress-finally-warns-customers-that-it-was-hacked\u002F","https:\u002F\u002Fwww.cafepress.com\u002F",23205290,"known",null,"unknown","Critical",[28,29,30,31,32],"Email addresses","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>The CafePress data breach exposed 23,205,290 unique email addresses and related account data in February 2019. The incident at the custom merchandise platform affected email addresses, names, phone numbers, physical addresses, and password hashes. Not every record contained every field, so the published total should not be read as evidence that all data types were present for every account. \u003Cstrong>23,205,290 unique email addresses\u003C\u002Fstrong> represent the verified account scope, while the availability of the other fields varied between records.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The verified core data types are email addresses, names, phone numbers, physical addresses, and passwords. Because passwords were stored as \u003Cstrong>SHA-1 hashes\u003C\u002Fstrong>, short or commonly used passwords faced an elevated risk of being recovered through offline guessing. Combining an email address with a name, phone number, or home address can make targeted phishing, fake delivery notices, telephone scams, and account-recovery abuse much more convincing. A regulatory investigation also reported millions of security questions and answers, more than 180,000 Social Security numbers, and tens of thousands of partial payment-card numbers and expiration dates. Those additional categories concerned narrower subsets and must not be interpreted as affecting all 23.2 million addresses. There is no verified basis for claiming that full card numbers, CVV codes, or financial data for every user were exposed.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The reference date for the incident is 20 February 2019. An attacker reportedly exploited security failures that month, and the company was informed about a vulnerability and stolen consumer data roughly one month later. Although the vulnerability was patched, a thorough investigation was delayed for months; an additional warning in April 2019 still did not lead to an immediate, clear disclosure to customers. Users were required to change passwords in August, but the request was initially presented as a general password-policy update. The failure to notify affected customers \u003Cstrong>until September 2019\u003C\u002Fstrong> extended the period in which stolen passwords and recovery answers could be abused. The precise initial-access technique was not publicly detailed, so attributing the incident to a specific exploit or attack method would be speculative.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>The broadest risk group consists of people whose email addresses were linked to CafePress accounts at the time of the incident. Anyone who reused the same password elsewhere faces credential-stuffing risk, while users whose names, addresses, or phone numbers were present may receive more personalized scams. People whose security-question answers were included should treat repeated answers on other services as compromised account-recovery secrets. The narrower group whose Social Security numbers were exposed faces a greater risk of identity theft and fraudulent account creation; users whose partial card details appeared should watch card activity and bank communications closely. Closing an account before the incident does not by itself prove that previously retained data was absent from the affected systems.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>Change the CafePress password and every identical or similar password used on another service, replacing each with a long, unique credential. Enable multi-factor authentication wherever it is available, and use a password manager to avoid future reuse. Update repeated security-question answers and verify the recovery email address and phone number attached to important accounts. Do not follow links in unexpected CafePress-themed password-reset, order, refund, or delivery messages; reach the service by typing the known address yourself. People specifically notified that a Social Security number may have been involved should review their credit reports and consider a fraud alert or credit freeze where appropriate. Anyone whose partial card information was affected should monitor transactions and promptly report suspicious activity to the card issuer.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Unique passwords, multi-factor authentication, and periodic account-recovery reviews provide the strongest reusable baseline. If an exposed email address cannot be changed, treat unexpected sign-in and reset messages as early warning signals. Because criminals can use real address, phone, and shopping context to make requests appear legitimate, verify urgent demands through a separate trusted channel. Users affected by identity data should monitor credit reports over time and, when closing unused accounts, separately request deletion or clarification of retention periods. For service operators, modern password hashing, encryption of sensitive identifiers, deletion of unnecessary data, tested incident response, and timely customer notification are durable controls that limit the harm from future breaches.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>Search your email address in LeakData to see whether it matches the CafePress breach record. Only check addresses that belong to you or that you are authorized to review. A match means the address appears in the verified dataset; it does not prove that the account was taken over or that every listed data type appeared in your individual record. An empty result should not override a security notice received through another trusted channel, because dataset coverage and verification can change over time. If there is a match, prioritize replacing reused passwords, then review recovery settings and financial activity according to the data categories relevant to you.\u003C\u002Fp>","","CafePress Data Breach (23.2 Million Reported Records)","CafePress Data Breach. 23.2 Million reported records were reported. Reported data: Email addresses, Names, Passwords. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Fcafepress_com.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":24},"Custom merchandise e-commerce","United States"]