Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

FTC’s CafePress Data-Breach Case: What Was Exposed, What the Orders Required, and Refund Status

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The CafePress breach happened in February 2019. The Federal Trade Commission announced its action in March 2022 and finalized administrative orders on June 24, 2022, after alleging that weak security practices left customer data vulnerable and that the company delayed or obscured breach notifications. The orders required security changes and $500,000 in consumer redress from CafePress’s former owner, Residual Pumpkin Entity LLC.

The original refund-claim deadline was March 10, 2024. The FTC later reported payments to eligible people who had filed valid claims, including a December 2025 round for certain people who had not redeemed earlier payments. That later payment round was not a general reopening of claims. Check the FTC’s official CafePress settlement page for any current payment information.

What happened in the CafePress breach?

According to the FTC complaint, an attacker exploited security weaknesses and accessed CafePress customer information during a major breach in February 2019. The complaint described exposed information that included:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Email addresses, names, and physical addresses.
  • Passwords that the FTC alleged were inadequately protected.
  • Answers to password-reset security questions, stored in readable form.
  • More than 180,000 Social Security numbers.
  • Tens of thousands of partial payment-card numbers and expiration dates.

The FTC said some of the information was later found for sale on the dark web. These are details alleged in the agency’s complaint; the case was resolved through administrative consent orders rather than a trial resolving every allegation. The FTC complaint provides the agency’s account and itemizes the types of information involved.

News reports commonly describe the incident as affecting about 23 million users or accounts. That figure is reported by TechCrunch; the FTC’s main announcements generally say “millions.” The larger figure does not mean that every account had the same information exposed, or that every affected person’s Social Security number was compromised.

Timeline: breach, FTC action, and refunds

  • February 2019: The major breach occurred, according to the FTC complaint.
  • March 2019: The FTC alleged that CafePress was warned about a vulnerability and unauthorized access.
  • April 2019: The complaint said a foreign government warned CafePress that customer account information had been obtained and urged notification.
  • September 2019: CafePress notified affected consumers, according to the FTC. The agency alleged that the notice came only after the breach had been publicly reported and that password changes were presented as part of a general policy update rather than clearly explained as a breach response.
  • 2020: PlanetArt LLC acquired CafePress.
  • March 15, 2022: The FTC announced its proposed action, alleging security failures, delayed or misleading disclosure, and email-marketing practices inconsistent with CafePress’s privacy representations.
  • June 24, 2022: The FTC finalized administrative orders involving Residual Pumpkin Entity LLC, CafePress’s former owner, and PlanetArt.
  • January 2024: The FTC announced a claims process and said it was notifying 184,491 consumers about possible eligibility.
  • March 10, 2024: The stated deadline to submit a claim passed.
  • September 2024: The FTC reported sending checks or PayPal payments to 20,044 consumers with valid claims, totaling more than $370,000.
  • December 2025: The FTC reported a later Zelle payment round for certain eligible people who had not cashed or accepted earlier payments.

The FTC’s 2022 announcement describes the allegations and the agency’s account of notification. The final-order announcement explains what the companies were required to do.

Why the FTC said CafePress’s security was inadequate

The FTC alleged that CafePress failed to use reasonable security practices. Among the practices cited in the agency’s account were:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Storing Social Security numbers and password-reset answers in plain, readable text.
  • Using inadequate password encryption and keeping personal information longer than necessary.
  • Failing to apply available protections against known vulnerabilities.
  • Lacking adequate procedures to detect, investigate, and respond to security incidents.
  • Allowing password resets based on answers attackers may already have obtained.
  • Failing to adequately investigate earlier compromised accounts and malware incidents.

Security questions are particularly risky when their answers are personal facts that may be exposed elsewhere or guessed. If an attacker can use an exposed answer to reset a password, changing that password once may not be enough. The password-reset route itself needs stronger protection.

What “cover-up” means in this case

“Cover-up” is a characterization of the FTC’s allegations, not a finding after a contested trial that intentional concealment was proved. The FTC alleged that CafePress received warnings about unauthorized access in March 2019, received a further warning in April, and did not properly investigate or notify affected customers promptly. It said consumers were not notified until September 2019, after public reporting, and that the company framed password changes as a general policy update rather than clearly explaining the breach.

The FTC also alleged that CafePress used customer email addresses for marketing in ways that conflicted with its privacy representations. The case was resolved through consent orders: they imposed obligations on the companies but are not the same as a court judgment following a trial on the factual claims.

What the final orders required

The orders imposed practical security and consumer-protection requirements. They required the companies to:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Replace security questions or similarly weak authentication methods with multifactor authentication.
  • Encrypt Social Security numbers.
  • Minimize the collection and retention of personal information.
  • Maintain a comprehensive information-security program.
  • Obtain independent third-party security assessments, including providing the FTC with a redacted version suitable for public disclosure.
  • Notify consumers whose personal information was accessed and provide information about protective steps.

The settlement involved two companies with different obligations. Residual Pumpkin Entity LLC, identified as CafePress’s former owner, was required to provide the monetary redress. Residual Pumpkin and PlanetArt were subject to information-security requirements; PlanetArt also had consumer-notification responsibilities. The orders do not, by themselves, establish that CafePress’s present-day practices comply with them.

How much money was involved—and who could receive it?

The $500,000 was redress required from Residual Pumpkin, not a simple fine paid by every affected account. The claims process was narrower than the population described in breach coverage. In January 2024, the FTC said it was notifying 184,491 consumers about possible eligibility to claim compensation related to exposed Social Security numbers. It later reported payments to 20,044 valid claimants, totaling more than $370,000.

Those figures describe different stages and groups: the number notified about possible eligibility, the number with valid claims paid in the reported distribution, and the total redress obligation are not interchangeable. An exposed email address alone did not mean someone automatically qualified for a payment, and the widely reported estimate of 23 million accounts should not be treated as the number of people entitled to compensation.

Can you still file a CafePress claim?

The original claims window has closed. The FTC’s January 2024 notice set March 10, 2024 as the deadline. The later FTC notices concern payments to people with previously approved claims, including some who had not redeemed earlier payments; they do not announce a new general opportunity for everyone affected to apply. The FTC settlement page is the authoritative place to check for payment updates.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What affected CafePress users should do now

  1. Change reused passwords. If you used your CafePress password on another site, replace it there with a unique password. Changing only the CafePress password does not protect other accounts where the same credentials remain in use.
  2. Turn on multifactor authentication. Prioritize email, banking, shopping, and other important accounts. Email access can be especially consequential because it may allow someone to reset passwords elsewhere.
  3. Reconsider security-question answers. If you reused answers across services, treat them as exposed. Where a service still requires security questions, use unique, hard-to-guess answers and store them securely.
  4. Review financial accounts and credit reports. Watch for unfamiliar transactions or accounts. Use AnnualCreditReport.com to access credit reports, and consider a credit freeze if you believe your Social Security number may have been exposed. A freeze is a free step that can make it harder for someone to open new credit in your name.
  5. Watch for targeted phishing. Old account details can make fraudulent messages sound convincing. Don’t use a link or phone number in an unsolicited message to check a breach payment; navigate to the official FTC page independently.
  6. Use free official guidance first. The FTC’s data-breach guidance and IdentityTheft.gov provide practical next steps. Paid identity-monitoring services are optional; monitoring cannot remove data that has already leaked and is not a substitute for account security or a credit freeze.

How to avoid a fake refund message

The FTC does not require an upfront payment to receive a refund. Do not pay a “processing” fee, share bank-login credentials, send cryptocurrency or gift cards, or grant remote access to your computer to someone claiming to administer a CafePress refund. If you receive a payment message, verify it by independently visiting the FTC’s official CafePress refund page rather than clicking the message’s link. A later notice about Zelle may relate to an eligible, previously approved claim; it does not mean claims have reopened for everyone.

What the case signals for businesses

The CafePress action illustrates recurring FTC enforcement concerns for companies that collect customer information: collect less, retain it only as long as needed, protect sensitive data with encryption, patch known vulnerabilities, and use strong authentication rather than relying on knowledge-based questions. Businesses also need procedures to detect incidents, investigate them promptly, escalate findings, and communicate accurately with affected people.

A privacy policy is not a substitute for operational controls. The FTC’s allegations included a mismatch between privacy representations and email-marketing practices, while its security allegations focused on how information was stored and how incidents were handled. For companies, the lesson is to make actual data handling, access controls, retention, incident response, and consumer disclosures consistent with what customers are told.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.