HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSFINANCIAL_ACCOUNTMediumContained
CafePress
bd_cc142fb5b6225699 · schema v1 · pii pii-v1
Full breach record for CafePress →CafePress Inc. notified South Carolina residents of a data security incident occurring on or about February 19, 2019. An unidentified third party obtained unauthorized access to customer information, including names, emails, passwords, SSNs/TINs, and limited credit card data. CafePress engaged outside experts and federal law enforcement, enhanced system security, and moved the affected database. Affected individuals were offered two years of Experian IdentityWorks.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_d2907b22ddc03bb6Oregon State AGfiled 2019-09-05(12d gap)Verified
- bd_e5a3738643f85841California State AGfiled 2019-09-05(12d gap)Verified
- bd_4ba35611bfd1f1d3Montana State AGfiled 2019-09-04(13d gap)Candidate
- bd_78faab83148350f7Washington State AGfiled 2019-09-04(13d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2019/CafePressIncorporated.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 17, 2019
- Raw hash
- 599a56f6ba7472ef6c14583396643777ded59a6ef0a3698f03439bd48ac46aa7
Reporting entity
- Name
- CafePressnorm: cafepress
- Domain
- cafepress.com
Victim entity
- Name
- CafePressnorm: cafepress
- Domain
- cafepress.com
Incident
- Discovered
- Feb 19, 2019
- Materiality determined
- —
- Notification sent
- Sep 3, 2019
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTCREDENTIALSFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Cooperating with federal law enforcement authorities
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(210 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.