HackingBrute ForceCustomer Data InvolvedCREDENTIALSLowContained
CafePress
bd_f62ddf7f517f9181 · schema v1 · pii pii-v1
Full breach record for CafePress →In July 2017, Zazzle detected a brute force attack where unauthorized parties used credentials obtained from other breaches to attempt logins to Zazzle accounts. Usernames (email addresses) and passwords were potentially compromised. Zazzle reset affected passwords and implemented CAPTCHA to prevent automated logins.
California clockDiscovered Jul 1, 2017 → Notified Aug 25, 201755d ✓ CA 60-day OK8 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-101384
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 25, 2017
- Raw hash
- 6378efcf2041bad5c923e776d1c584178c3d8c9fbe62439e1a71fe0133fd5b5c
Reporting entity
- Name
- CafePressnorm: cafepress
- Domain
- cafepress.com
Victim entity
- Name
- CafePressnorm: cafepress
- Domain
- cafepress.com
Incident
- Discovered
- Jul 1, 2017
- Materiality determined
- —
- Notification sent
- Aug 25, 2017
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALS
- Attack vector
- Unknown
- MITRE ATT&CK
- T1110 Brute Force
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 weeks(55 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 55d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jul 1, 2017→ Notified: Aug 25, 201755d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.