CafePress
bd_9c163ca0f10ed5f1 · schema v1 · pii pii-v1
Full breach record for CafePress →CafePress notified customers that an unidentified third party obtained unauthorized access to a database containing personal information on or about February 19, 2019. Affected data included names, email addresses, passwords, physical addresses, phone numbers, Social Security Numbers, Tax Identification Numbers, and in some cases, the last four digits of credit card numbers and expiration dates. CafePress engaged outside experts, cooperated with federal law enforcement, and moved the affected database. The company offered two years of complimentary credit monitoring and identity theft resolution services through Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 19, 2019
Begins
Sep 4, 2019
Filed
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Montana State AGbd_4ba35611bfd1f1d32019-09-04Candidate
- Washington State AGbd_78faab83148350f72019-09-04Verified
- New Hampshire State AGbd_160cb0d78c4d66ba2019-09-05 · +1dVerified
- Oregon State AGbd_d2907b22ddc03bb62019-09-05 · +1dVerified
Show 3 more filings ↓Show fewer ↑up to 13d gap
- California State AGbd_e5a3738643f858412019-09-05 · +1dVerified
- Massachusetts State AGbd_c005bb5f635169d52019-09-06 · +2dVerified
- South Carolina State AGbd_cc142fb5b62256992019-09-17 · +13dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Sep 4 (MT), last Sep 17 (SC) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.