FTC Cracks Down on CafePress for Data Breach Cover-Up

FTC Cracks Down on CafePress for Data Breach Cover-Up

In a recent and significant enforcement action, the Federal Trade Commission (“FTC”) has taken steps to hold e-commerce platform CafePress accountable for its mishandling of sensitive consumer data. The company has been accused of failing to secure personal data, resulting in a major data breach that exposed millions of individuals to potential fraud and identity theft. Moreover, the FTC alleges that CafePress attempted to conceal the breach from consumers, exacerbating the impact of the security failure. The FTC's case centers around the company’s negligence in securing sensitive information, including Social Security numbers, password reset answers, and encrypted passwords. According to the complaint, the company stored this sensitive data in plain text, making it vulnerable to exploitation. Furthermore, CafePress did not use adequate encryption and failed to implement basic security measures, such as multi-factor authentication, to protect users from unauthorized access. The breach itself, which occurred in February 2019, allowed hackers to access millions of email addresses, passwords, physical addresses, and even partial payment card information. Among the most concerning breaches was the exposure of over 180,000 unencrypted Social Security numbers, some of which were later found for sale on the dark web. Despite receiving multiple warnings, including a government alert and direct notice of the breach, CafePress took months to inform consumers, not notifying them until September 2019, over six months after the breach occurred.

You need to login or register for an account in order to view the full content of this page.

Select the Option that's Right for You

CLIClaw Subscription

 

Empower Your Compliance Journey.

Here you will find access to a collection of proven materials used to design compliance programs for some of the largest marketers including online education, simplified guides, and checklists, as well as public resources, programs and outlines which are designed to assist you in creating your community of compliance.

$279

per year
  • Educational Resources. Gain insights into designing robust compliance programs used by leading marketers. Simplified guides, checklists, and public resources are at your fingertips.
  • Customizable Policies. Empower your team to create personalized policies, procedures, and contracts tailored to your business needs. Learn negotiation strategies to handle contracts effectively and mitigate risks.
  • Practical Solutions. Navigate seemingly intricate compliance challenges with practical, actionable solutions.
  • Knowledge Empowerment. Understand legal requirements to transform complex forms into actionable insights and strategic advantages.
And More! Continuous updates and additional resources to keep you ahead in compliance.

CLICEnterprise

 

Tailored Compliance Solutions for Your Business.

Contact Us Today to Get Started

  • Tailored Guides & Checklists. Customized compliance guides and checklists specific to your industry and operational requirements.
  • Company Private Web Portal. Secure access to a dedicated web portal for centralized compliance management, training, and documentation.
  • Certified Personal Training. Expert-led training programs tailored to your company’s practices and compliance requirements.
  • Compliance Alerts. Stay informed with timely alerts on regulatory changes and updates impacting your industry.
And More! Additional resources and support to streamline your compliance processes.