Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The CafePress breach happened in February 2019. The Federal Trade Commission announced its action in March 2022 and finalized administrative orders on June 24, 2022, after alleging that weak security practices left customer data vulnerable and that the company delayed or obscured breach notifications. The orders required security changes and $500,000 in consumer redress from CafePress’s former owner, Residual Pumpkin Entity LLC.
The original refund-claim deadline was March 10, 2024. The FTC later reported payments to eligible people who had filed valid claims, including a December 2025 round for certain people who had not redeemed earlier payments. That later payment round was not a general reopening of claims. Check the FTC’s official CafePress settlement page for any current payment information.
What happened in the CafePress breach?
According to the FTC complaint, an attacker exploited security weaknesses and accessed CafePress customer information during a major breach in February 2019. The complaint described exposed information that included:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Email addresses, names, and physical addresses.
- Passwords that the FTC alleged were inadequately protected.
- Answers to password-reset security questions, stored in readable form.
- More than 180,000 Social Security numbers.
- Tens of thousands of partial payment-card numbers and expiration dates.
The FTC said some of the information was later found for sale on the dark web. These are details alleged in the agency’s complaint; the case was resolved through administrative consent orders rather than a trial resolving every allegation. The FTC complaint provides the agency’s account and itemizes the types of information involved.
#1 Best Overall
News reports commonly describe the incident as affecting about 23 million users or accounts. That figure is reported by TechCrunch; the FTC’s main announcements generally say “millions.” The larger figure does not mean that every account had the same information exposed, or that every affected person’s Social Security number was compromised.
Timeline: breach, FTC action, and refunds
- February 2019: The major breach occurred, according to the FTC complaint.
- March 2019: The FTC alleged that CafePress was warned about a vulnerability and unauthorized access.
- April 2019: The complaint said a foreign government warned CafePress that customer account information had been obtained and urged notification.
- September 2019: CafePress notified affected consumers, according to the FTC. The agency alleged that the notice came only after the breach had been publicly reported and that password changes were presented as part of a general policy update rather than clearly explained as a breach response.
- 2020: PlanetArt LLC acquired CafePress.
- March 15, 2022: The FTC announced its proposed action, alleging security failures, delayed or misleading disclosure, and email-marketing practices inconsistent with CafePress’s privacy representations.
- June 24, 2022: The FTC finalized administrative orders involving Residual Pumpkin Entity LLC, CafePress’s former owner, and PlanetArt.
- January 2024: The FTC announced a claims process and said it was notifying 184,491 consumers about possible eligibility.
- March 10, 2024: The stated deadline to submit a claim passed.
- September 2024: The FTC reported sending checks or PayPal payments to 20,044 consumers with valid claims, totaling more than $370,000.
- December 2025: The FTC reported a later Zelle payment round for certain eligible people who had not cashed or accepted earlier payments.
The FTC’s 2022 announcement describes the allegations and the agency’s account of notification. The final-order announcement explains what the companies were required to do.
Why the FTC said CafePress’s security was inadequate
The FTC alleged that CafePress failed to use reasonable security practices. Among the practices cited in the agency’s account were:
- Storing Social Security numbers and password-reset answers in plain, readable text.
- Using inadequate password encryption and keeping personal information longer than necessary.
- Failing to apply available protections against known vulnerabilities.
- Lacking adequate procedures to detect, investigate, and respond to security incidents.
- Allowing password resets based on answers attackers may already have obtained.
- Failing to adequately investigate earlier compromised accounts and malware incidents.
Security questions are particularly risky when their answers are personal facts that may be exposed elsewhere or guessed. If an attacker can use an exposed answer to reset a password, changing that password once may not be enough. The password-reset route itself needs stronger protection.
What “cover-up” means in this case
“Cover-up” is a characterization of the FTC’s allegations, not a finding after a contested trial that intentional concealment was proved. The FTC alleged that CafePress received warnings about unauthorized access in March 2019, received a further warning in April, and did not properly investigate or notify affected customers promptly. It said consumers were not notified until September 2019, after public reporting, and that the company framed password changes as a general policy update rather than clearly explaining the breach.
The FTC also alleged that CafePress used customer email addresses for marketing in ways that conflicted with its privacy representations. The case was resolved through consent orders: they imposed obligations on the companies but are not the same as a court judgment following a trial on the factual claims.
What the final orders required
The orders imposed practical security and consumer-protection requirements. They required the companies to:
- Replace security questions or similarly weak authentication methods with multifactor authentication.
- Encrypt Social Security numbers.
- Minimize the collection and retention of personal information.
- Maintain a comprehensive information-security program.
- Obtain independent third-party security assessments, including providing the FTC with a redacted version suitable for public disclosure.
- Notify consumers whose personal information was accessed and provide information about protective steps.
The settlement involved two companies with different obligations. Residual Pumpkin Entity LLC, identified as CafePress’s former owner, was required to provide the monetary redress. Residual Pumpkin and PlanetArt were subject to information-security requirements; PlanetArt also had consumer-notification responsibilities. The orders do not, by themselves, establish that CafePress’s present-day practices comply with them.
How much money was involved—and who could receive it?
The $500,000 was redress required from Residual Pumpkin, not a simple fine paid by every affected account. The claims process was narrower than the population described in breach coverage. In January 2024, the FTC said it was notifying 184,491 consumers about possible eligibility to claim compensation related to exposed Social Security numbers. It later reported payments to 20,044 valid claimants, totaling more than $370,000.
Those figures describe different stages and groups: the number notified about possible eligibility, the number with valid claims paid in the reported distribution, and the total redress obligation are not interchangeable. An exposed email address alone did not mean someone automatically qualified for a payment, and the widely reported estimate of 23 million accounts should not be treated as the number of people entitled to compensation.
Can you still file a CafePress claim?
The original claims window has closed. The FTC’s January 2024 notice set March 10, 2024 as the deadline. The later FTC notices concern payments to people with previously approved claims, including some who had not redeemed earlier payments; they do not announce a new general opportunity for everyone affected to apply. The FTC settlement page is the authoritative place to check for payment updates.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What affected CafePress users should do now
- Change reused passwords. If you used your CafePress password on another site, replace it there with a unique password. Changing only the CafePress password does not protect other accounts where the same credentials remain in use.
- Turn on multifactor authentication. Prioritize email, banking, shopping, and other important accounts. Email access can be especially consequential because it may allow someone to reset passwords elsewhere.
- Reconsider security-question answers. If you reused answers across services, treat them as exposed. Where a service still requires security questions, use unique, hard-to-guess answers and store them securely.
- Review financial accounts and credit reports. Watch for unfamiliar transactions or accounts. Use AnnualCreditReport.com to access credit reports, and consider a credit freeze if you believe your Social Security number may have been exposed. A freeze is a free step that can make it harder for someone to open new credit in your name.
- Watch for targeted phishing. Old account details can make fraudulent messages sound convincing. Don’t use a link or phone number in an unsolicited message to check a breach payment; navigate to the official FTC page independently.
- Use free official guidance first. The FTC’s data-breach guidance and IdentityTheft.gov provide practical next steps. Paid identity-monitoring services are optional; monitoring cannot remove data that has already leaked and is not a substitute for account security or a credit freeze.
How to avoid a fake refund message
The FTC does not require an upfront payment to receive a refund. Do not pay a “processing” fee, share bank-login credentials, send cryptocurrency or gift cards, or grant remote access to your computer to someone claiming to administer a CafePress refund. If you receive a payment message, verify it by independently visiting the FTC’s official CafePress refund page rather than clicking the message’s link. A later notice about Zelle may relate to an eligible, previously approved claim; it does not mean claims have reopened for everyone.
Best Value
What the case signals for businesses
The CafePress action illustrates recurring FTC enforcement concerns for companies that collect customer information: collect less, retain it only as long as needed, protect sensitive data with encryption, patch known vulnerabilities, and use strong authentication rather than relying on knowledge-based questions. Businesses also need procedures to detect incidents, investigate them promptly, escalate findings, and communicate accurately with affected people.
A privacy policy is not a substitute for operational controls. The FTC’s allegations included a mismatch between privacy representations and email-marketing practices, while its security allegations focused on how information was stored and how incidents were handled. For companies, the lesson is to make actual data handling, access controls, retention, incident response, and consumer disclosures consistent with what customers are told.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

