Skip to content

CafePress

Disclosed Aug 5, 20197 years ago23,000,000 affectedSettled

Official notice

2019 breach of 23M users covered up; FTC order and USD 500,000 redress

Hackers breached CafePress servers in February 2019 and published data on more than 23 million users, including emails, weakly protected passwords, security answers and over 180,000 plaintext Social Security numbers. The FTC said the company concealed the breach and ordered former owner Residual Pumpkin to pay USD 500,000 to compensate small businesses.

What is known

People affected23,000,000 (as reported by the organization)
DisclosedAug 5, 2019
DiscoveredAug 6, 2019
HappenedFeb 19, 2019
AttackHacking
Data exposedNames, Credentials and tokens, Emails, Passwords, Phone numbers, Addresses, Social Security numbers, Other
SectorRetail · US
StatusSettled
Lawsuit or fineUSD 2M seven-AG agreement led by New York (Dec 2020); FTC orders with USD 500,000 redress (March 2022) (about $2.5M)
Check your emailHave I Been Pwned

Sources

Source
California Attorney General breach notice: CafePressoag.ca.gov · Official notice
Washington Attorney General breach notice: CafePressatg.wa.gov · Official notice
Notice letter filed with the Delaware DOJ: CafePressattorneygeneral.delaware.gov · Official notice
Oregon DOJ breach notice: CafePressjustice.oregon.gov · Official notice
Have I Been Pwned: CafePresshaveibeenpwned.com · Aggregator
NY AG: USD 2 Million agreement with CafePress after data breachag.ny.gov · Regulator
FTC to fine CafePress for covering up 2019 data breachtechcrunch.com · News
FTC Takes Action Against CafePress for Data Breach Cover Upftc.gov · Regulator
Maine Attorney General breach notice archive: CafePressmaine.gov · Official notice

Notices filed

WhereFiledPeople
Have I Been Pwnedaccounts in the dataAug 5, 201923,205,290
ResearchtotalAug 5, 201923,000,000
Washington AGresidents of WASep 4, 20195,863
Delaware DOJresidents of DESep 4, 201954,797
California AGresidents of CASep 5, 2019
Oregon DOJresidents of ORSep 5, 201922,000,000
Maine AGresidents of MESep 5, 2019
History of this record
  • 2026-09-25 · source: empty to https://www.maine.gov/ag/sites/maine.gov.ag/files/docs/Data%20breach%20spreadsheet%2012-6-2018%20through%209-14-2020%20REDACTED.xlsx · backfill source
  • 2026-09-25 · status: confirmed to settled · seed source
  • 2026-09-25 · fine_usd: empty to 2500000 · seed source
  • 2026-09-25 · lawsuit: empty to USD 2M seven-AG agreement led by New York (Dec 2020); FTC orders with USD 500,000 redress (March 2022) · seed source
  • 2026-09-25 · sector: tech to retail · seed source
  • 2026-09-25 · data_types: ["names","credentials","emails","passwords","phone","addresses"] to ["names","credentials","emails","passwords","phone","addresses","ssn","other"] · seed source
  • 2026-09-25 · records_basis: hibp to organization · seed source
  • 2026-09-25 · records: 23205290 to 23000000 · seed source
  • 2026-09-25 · summary: In February 2019, the custom merchandise retailer CafePress suffered a data breach. The exposed data included 23 million unique email addresses with some records also containing names, physical addresses, phone numbers and passwords stored to Hackers breached CafePress servers in February 2019 and published data on more than 23 million users, including emails, weakly protected passwords, security answers and over 180,000 plaintext Social Security numbers. The FTC said the compan · seed source
  • 2026-09-25 · title: empty to 2019 breach of 23M users covered up; FTC order and USD 500,000 redress · seed source
  • 2026-09-25 · hibp: empty to CafePress · backfill source
  • 2026-09-25 · sector: other to tech · backfill source
  • 2026-09-25 · data_types: ["names","credentials"] to ["names","credentials","emails","passwords","phone","addresses"] · backfill source
  • 2026-09-25 · records_basis: empty to hibp · backfill source
  • 2026-09-25 · records: empty to 23205290 · backfill source
  • 2026-09-25 · disclosed: 2019-09-04 to 2019-08-05 · backfill source
  • 2026-09-25 · summary: empty to In February 2019, the custom merchandise retailer CafePress suffered a data breach. The exposed data included 23 million unique email addresses with some records also containing names, physical addresses, phone numbers and passwords stored · backfill source
  • 2026-09-25 · data_types: [] to ["names","credentials"] · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · disclosed: 2019-09-05 to 2019-09-04 · backfill source
  • 2026-09-25 · discovered: empty to 2019-08-06 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about CafePress

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.