Latest in Gear

Image credit: SIPA USA/PA Images

CafePress resets passwords months after reported data breach

About 23 million accounts were apparently compromised.
121 Shares
Share
Tweet
Share
Save

Sponsored Links

SIPA USA/PA Images

StockX isn't the only company that appears to have warned users about a data breach through password resets. T-shirt seller CafePress has been asking customers to choose new passwords as part of an updated "password policy," but the news came soon after reports that the site had been the victim of a data breach in February. Have I Been Pwned claimed that over 23.2 million accounts had been exposed, including email addresses, names, physical addresses and phone numbers.

We've asked CafePress if it can comment, although there don't appear haven't been any notification emails or formal disclosures mentioning a breach. About 77 percent of the email addresses in the breach have shown up in previous HIBP breach alerts.

Provided the reports of a breach are accurate, they raise a number of questions. How recently did CafePress learn of the breach? Has it done anything else to improve security? And why would it only acknowledge a breach through a password reset that doesn't even mention the security incident? There has been pressure for clearer data breach disclosures, and this could be a textbook example of why. Many users might not even know that there was a breach, let alone how it affects their personal info.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
121 Shares
Share
Tweet
Share
Save

Popular on Engadget

Engadget's Guide to Privacy

Engadget's Guide to Privacy

View
Oppo's next phone can be fully charged in just 30 minutes

Oppo's next phone can be fully charged in just 30 minutes

View
Fossil's latest hybrid watch is likely powered by Wear OS

Fossil's latest hybrid watch is likely powered by Wear OS

View
Sonos Move review: Versatility doesn't come cheap

Sonos Move review: Versatility doesn't come cheap

View
ZenBook Pro Duo review: ASUS makes a case for dual-screen laptops

ZenBook Pro Duo review: ASUS makes a case for dual-screen laptops

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr