CafePress
bd_e5a3738643f85841 · schema v1 · pii pii-v1
Full breach record for CafePress →CafePress Inc. notified California residents that an unidentified third party obtained customer information from a database on or about February 19, 2019. Affected data included names, email addresses, passwords, physical addresses, phone numbers, Social Security Numbers, Tax Identification Numbers, and in some cases, the last four digits of credit card numbers and expiration dates. CafePress engaged outside experts, cooperated with federal law enforcement, and moved the affected database. The company offered two years of Experian IdentityWorks credit monitoring and identity theft resolution services.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 19, 2019
Begins
Sep 5, 2019
Filed
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- New Hampshire State AGbd_160cb0d78c4d66ba2019-09-05Verified
- Oregon State AGbd_d2907b22ddc03bb62019-09-05Verified
- Massachusetts State AGbd_c005bb5f635169d52019-09-06 · +1dVerified
- Montana State AGbd_4ba35611bfd1f1d32019-09-04 · +1dCandidate
Show 3 more filings ↓Show fewer ↑up to 12d gap
- Washington State AGbd_78faab83148350f72019-09-04 · +1dVerified
- Delaware State AGbd_9c163ca0f10ed5f12019-09-04 · +1dVerified
- South Carolina State AGbd_cc142fb5b62256992019-09-17 · +12dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Sep 4 (MT), last Sep 17 (SC) — a 13-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.