CafePress

NJCCIC Data Breach Notification

Original Release Date: 8/12/2019

Summary

CafePress, a custom T-shirt and merchandise company, has suffered a breach that compromised approximately 23.2 million accounts. CafePress claims an update to their password policy initiated the mass password reset this week; however, at the time of this writing, the company has not acknowledged the breach. Compromised information includes email addresses, names, phone numbers, and physical addresses, which can be used by threat actors to further propagate illicit social engineering attempts. Approximately 12 million users’ passwords may have also been exposed, according to Troy Hunt, the founder of Have I Been Pwned, a site which allows users to verify if their account information may have been compromised due to a breach. Impacted customers are advised to change passwords, avoid reusing compromised credentials, and monitor accounts for suspicious activity.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.