CafePress notified customers in Delaware and other states that an unidentified third party unauthorizedly accessed customer data from a CafePress database around February 19, 2019. The breach exposed names, emails, passwords, SSNs/TINs, and in some cases credit card details. CafePress engaged outside experts and federal law enforcement, secured the database, and offered two years of Experian IdentityWorks monitoring.