HomeSecurityCafePress: Personal information of 23 million users leaked

CafePress: Personal information of 23 million users leaked

CafePress , a well-known American shopping site , has suffered a serious breach data that affected millions of customers. Specifically, the number of users affected exceeds 23 million .CafePress

Customers, however, were not notified of the breach incident by the site itself but by Troy Hunt's service , "Have I Pwned."

When Hunt heard about the leak , he sought the help of security researcher Jim Scott, with whom he had previously worked on other data breaches, such as the Evite site.

Scott said he was notified by Troy about the CafePress.com data leak about two weeks ago. At that time, it appeared that the source of the breach was the search engine WeleakInfo . Scott and his colleagues began investigating the case further to identify the vulnerable database that exposed the data of millions of CafePress customers.

According to another investigation, a vulnerable CafePress database containing approximately 493,000 accountswas found for sale on hacking forums. However, it is not yet certain that this is the same breach incident.

According to “Have I Been Pwned?”, CafePress was hacked in February 2019, exposing the personal information of 23,205,290 users. The compromised data includes email, names, passwords, phone numbers, and home addresses.

Scott also said that half of the compromised passwords were encoded with the base64 SHA1 algorithm, which is very weak by today's standards. Other users who logged in via Facebook and Amazon did not have compromised passwords.

CafePress has not officially announced the breach, but users are being prompted to reset passwords when they try to log in to the site, which suggests something is probably wrong.

CafePress: Personal information of 23 million users leaked

Password resets are not enough

When a data breach becomes known, companies should inform usersso they can take appropriate protective measures.

Yet once again, in just a week, a company has decided that resetting a password is the first step in exposing a breach. A few days ago, StockX followed suit. Now, CafePress has followed suit.

Password reset notifications should be made at the same time as are notified of the breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS