HackingStolen CredentialsData ExfiltratedCREDENTIALSPIILowContained
CafePress
bd_eeb1d318d36e6247 · schema v1 · pii pii-v1
Full breach record for CafePress →Zazzle Inc. reported a data breach affecting California residents. The incident involved unauthorized login attempts using credentials obtained from a separate data breach of another website. Zazzle detected the activity and reset affected user passwords. The breach exposed usernames and passwords.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-63988
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 21, 2016
- Raw hash
- 7c4dbbecdc5079eadffdf4536c89312e53131456088ef5b25dd53fa9bb330df2
Reporting entity
- Name
- CafePressnorm: cafepress
- Domain
- cafepress.com
Victim entity
- Name
- CafePressnorm: cafepress
- Domain
- cafepress.com
Incident
- Discovered
- Aug 22, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.