Security News > 2022 > March > FTC to fine CafePress for cover up of massive data breach

The U.S. Federal Trade Commission wants to slap the former owner of the CafePress custom t-shirt and merchandise site with a $500,000 fine for failing to secure its users' data and attempting to cover up a significant data breach impacting millions.
As the consumer protection watchdog explained, CafePress' former owner, Residual Pumpkin Entity, stored its customers' Social Security numbers and password reset answers in plain text, and their data longer than necessary.
"As a result of its shoddy security practices, CafePress' network was breached multiple times," the FTC said today.
CafePress purportedly tried to cover up this massive data breach and did not inform any of the impacted customers until September 2019, one month after BleepingComputer reported the breach.
CafePress was also aware that it had data security problems even before the 2019 data breach.
The FTC added that CafePress also allegedly "Misled users by using consumer email addresses for marketing despite its promises that such information would only be used to fulfill orders consumers had placed."
News URL
Related news
- StreamElements discloses third-party data breach after hacker leaks data (source)
- Texas State Bar warns of data breach after INC ransomware claims attack (source)
- Food giant WK Kellogg discloses data breach linked to Clop ransomware (source)
- The quiet data breach hiding in AI workflows (source)
- Hertz confirms customer info, drivers' licenses stolen in data breach (source)
- Hertz data breach: Customers in US, EU, UK, Australia and Canada affected (source)
- Landmark Admin data breach impact now reaches 1.6 million people (source)
- Entertainment services giant Legends International discloses data breach (source)
- 2025 Data Breach Investigations Report: Third-party breaches double (source)
- Yale New Haven Health data breach affects 5.5 million patients (source)