Latest in Gear

Image credit: SIPA USA/PA Images

CafePress resets passwords months after reported data breach

About 23 million accounts were apparently compromised.
121 Shares
Share
Tweet
Share
Save

Sponsored Links

SIPA USA/PA Images

StockX isn't the only company that appears to have warned users about a data breach through password resets. T-shirt seller CafePress has been asking customers to choose new passwords as part of an updated "password policy," but the news came soon after reports that the site had been the victim of a data breach in February. Have I Been Pwned claimed that over 23.2 million accounts had been exposed, including email addresses, names, physical addresses and phone numbers.

We've asked CafePress if it can comment, although there don't appear haven't been any notification emails or formal disclosures mentioning a breach. About 77 percent of the email addresses in the breach have shown up in previous HIBP breach alerts.

Provided the reports of a breach are accurate, they raise a number of questions. How recently did CafePress learn of the breach? Has it done anything else to improve security? And why would it only acknowledge a breach through a password reset that doesn't even mention the security incident? There has been pressure for clearer data breach disclosures, and this could be a textbook example of why. Many users might not even know that there was a breach, let alone how it affects their personal info.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
121 Shares
Share
Tweet
Share
Save

Popular on Engadget

The 2019 Engadget Holiday Gift Guide

The 2019 Engadget Holiday Gift Guide

View
AT&T will bring real 5G to millions of customers this year

AT&T will bring real 5G to millions of customers this year

View
Tesla's electric ATV matches well with the Cybertruck

Tesla's electric ATV matches well with the Cybertruck

View
Tesla unveils its Cybertruck, with a price starting at $39,900

Tesla unveils its Cybertruck, with a price starting at $39,900

View
Lotus puts its electric Evija hypercar prototype on the track

Lotus puts its electric Evija hypercar prototype on the track

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr