CafePress
Disclosed Aug 5, 20197 years ago23,000,000 affectedSettled
2019 breach of 23M users covered up; FTC order and USD 500,000 redress
Hackers breached CafePress servers in February 2019 and published data on more than 23 million users, including emails, weakly protected passwords, security answers and over 180,000 plaintext Social Security numbers. The FTC said the company concealed the breach and ordered former owner Residual Pumpkin to pay USD 500,000 to compensate small businesses.
What is known
| People affected | 23,000,000 (as reported by the organization) |
|---|---|
| Disclosed | Aug 5, 2019 |
| Discovered | Aug 6, 2019 |
| Happened | Feb 19, 2019 |
| Attack | Hacking |
| Data exposed | Names, Credentials and tokens, Emails, Passwords, Phone numbers, Addresses, Social Security numbers, Other |
| Sector | Retail · US |
| Status | Settled |
| Lawsuit or fine | USD 2M seven-AG agreement led by New York (Dec 2020); FTC orders with USD 500,000 redress (March 2022) (about $2.5M) |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: CafePressoag.ca.gov · Official notice | Official notice |
| Washington Attorney General breach notice: CafePressatg.wa.gov · Official notice | Official notice |
| Notice letter filed with the Delaware DOJ: CafePressattorneygeneral.delaware.gov · Official notice | Official notice |
| Oregon DOJ breach notice: CafePressjustice.oregon.gov · Official notice | Official notice |
| Have I Been Pwned: CafePresshaveibeenpwned.com · Aggregator | Aggregator |
| NY AG: USD 2 Million agreement with CafePress after data breachag.ny.gov · Regulator | Regulator |
| FTC to fine CafePress for covering up 2019 data breachtechcrunch.com · News | News |
| FTC Takes Action Against CafePress for Data Breach Cover Upftc.gov · Regulator | Regulator |
| Maine Attorney General breach notice archive: CafePressmaine.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | Aug 5, 2019 | 23,205,290 |
| Researchtotal | Aug 5, 2019 | 23,000,000 |
| Washington AGresidents of WA | Sep 4, 2019 | 5,863 |
| Delaware DOJresidents of DE | Sep 4, 2019 | 54,797 |
| California AGresidents of CA | Sep 5, 2019 | |
| Oregon DOJresidents of OR | Sep 5, 2019 | 22,000,000 |
| Maine AGresidents of ME | Sep 5, 2019 |
History of this record
- 2026-09-25 · source: empty to https://www.maine.gov/ag/sites/maine.gov.ag/files/docs/Data%20breach%20spreadsheet%2012-6-2018%20through%209-14-2020%20REDACTED.xlsx · backfill source
- 2026-09-25 · status: confirmed to settled · seed source
- 2026-09-25 · fine_usd: empty to 2500000 · seed source
- 2026-09-25 · lawsuit: empty to USD 2M seven-AG agreement led by New York (Dec 2020); FTC orders with USD 500,000 redress (March 2022) · seed source
- 2026-09-25 · sector: tech to retail · seed source
- 2026-09-25 · data_types: ["names","credentials","emails","passwords","phone","addresses"] to ["names","credentials","emails","passwords","phone","addresses","ssn","other"] · seed source
- 2026-09-25 · records_basis: hibp to organization · seed source
- 2026-09-25 · records: 23205290 to 23000000 · seed source
- 2026-09-25 · summary: In February 2019, the custom merchandise retailer CafePress suffered a data breach. The exposed data included 23 million unique email addresses with some records also containing names, physical addresses, phone numbers and passwords stored to Hackers breached CafePress servers in February 2019 and published data on more than 23 million users, including emails, weakly protected passwords, security answers and over 180,000 plaintext Social Security numbers. The FTC said the compan · seed source
- 2026-09-25 · title: empty to 2019 breach of 23M users covered up; FTC order and USD 500,000 redress · seed source
- 2026-09-25 · hibp: empty to CafePress · backfill source
- 2026-09-25 · sector: other to tech · backfill source
- 2026-09-25 · data_types: ["names","credentials"] to ["names","credentials","emails","passwords","phone","addresses"] · backfill source
- 2026-09-25 · records_basis: empty to hibp · backfill source
- 2026-09-25 · records: empty to 23205290 · backfill source
- 2026-09-25 · disclosed: 2019-09-04 to 2019-08-05 · backfill source
- 2026-09-25 · summary: empty to In February 2019, the custom merchandise retailer CafePress suffered a data breach. The exposed data included 23 million unique email addresses with some records also containing names, physical addresses, phone numbers and passwords stored · backfill source
- 2026-09-25 · data_types: [] to ["names","credentials"] · backfill source
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · disclosed: 2019-09-05 to 2019-09-04 · backfill source
- 2026-09-25 · discovered: empty to 2019-08-06 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.