CafePress
bd_4ba35611bfd1f1d3 · schema v1 · pii pii-v1
Full breach record for CafePress →CafePress Inc. notified Montana AG of a data security incident occurring on or about February 19, 2019. An unidentified third party obtained unauthorized access to customer database information including names, emails, passwords, SSNs/TINs, and in some cases credit card details. CafePress engaged outside experts and federal law enforcement, enhanced system security, and moved the affected database. Affected individuals were offered two years of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 19, 2019
Begins
Feb 19, 2019
Discovered
Sep 4, 2019
Filed
vs. sector median
+20 wks slower
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Washington State AGbd_78faab83148350f72019-09-04Verified
- Delaware State AGbd_9c163ca0f10ed5f12019-09-04Verified
- New Hampshire State AGbd_160cb0d78c4d66ba2019-09-05 · +1dVerified
- Oregon State AGbd_d2907b22ddc03bb62019-09-05 · +1dVerified
Show 3 more filings ↓Show fewer ↑up to 13d gap
- California State AGbd_e5a3738643f858412019-09-05 · +1dVerified
- Massachusetts State AGbd_c005bb5f635169d52019-09-06 · +2dVerified
- South Carolina State AGbd_cc142fb5b62256992019-09-17 · +13dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Sep 4 (WA), last Sep 17 (SC) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.