CafePress
ent_b91d2d7ab0b421a599b50e1d
Disclosures
8
State AG · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
22,000,000
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CafePress
- Normalized
- cafepress— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cafepress.com
Disclosure history (8)newest first
- 🌴South Carolina State AGas victim2019-09-17
CafePress Inc. notified South Carolina residents of a data security incident occurring on or about February 19, 2019. An unidentified third party obtained unauthorized access to customer information, including names, emails, passwords, SSNs/TINs, and limited credit card data. CafePress engaged outside experts and federal law enforcement, enhanced system security, and moved the affected database. Affected individuals were offered two years of Experian IdentityWorks.
- 🦫Oregon State AGas victim2019-09-05
CafePress Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2019-09-05. 22,000,000 individuals were affected.
- 🐻California State AGas victim2019-09-05
CafePress Inc. notified California residents that an unidentified third party obtained customer information from a database on or about February 19, 2019. Affected data included names, email addresses, passwords, physical addresses, phone numbers, Social Security Numbers, Tax Identification Numbers, and in some cases, the last four digits of credit card numbers and expiration dates. CafePress engaged outside experts, cooperated with federal law enforcement, and moved the affected database. The company offered two years of Experian IdentityWorks credit monitoring and identity theft resolution services.
- 🦬Montana State AGas victim2019-09-04
CafePress Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2019-09-04. The breach occurred from 2/19/2019 to 8/6/2019. 49,515 Montana residents were affected.
- 🌲Washington State AGas victim2019-09-04
CafePress, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2019-08-06 and filed notice on 2019-09-04. 5,863 Washington residents were affected. 29 days elapsed between awareness and notification. 168 days to identify the breach. 0 days to contain the breach.
- 💎Delaware State AGas victim2019-09-04
CafePress notified customers in Delaware and other states that an unidentified third party unauthorizedly accessed customer data from a CafePress database around February 19, 2019. The breach exposed names, emails, passwords, SSNs/TINs, and in some cases credit card details. CafePress engaged outside experts and federal law enforcement, secured the database, and offered two years of Experian IdentityWorks monitoring.
- 🐻California State AGas victim2017-08-25
In July 2017, Zazzle detected a brute force attack where unauthorized parties used credentials obtained from other breaches to attempt logins to Zazzle accounts. Usernames (email addresses) and passwords were potentially compromised. Zazzle reset affected passwords and implemented CAPTCHA to prevent automated logins.
- 🐻California State AGas victim2016-09-21
Zazzle Inc. reported a data breach affecting California residents. The incident involved unauthorized login attempts using credentials obtained from a separate data breach of another website. Zazzle detected the activity and reset affected user passwords. The breach exposed usernames and passwords.