CafePress , a well-known American shopping site , has suffered a serious breach data that affected millions of customers. Specifically, the number of users affected exceeds 23 million .
Customers, however, were not notified of the breach incident by the site itself but by Troy Hunt's service , "Have I Pwned."
When Hunt heard about the leak , he sought the help of security researcher Jim Scott, with whom he had previously worked on other data breaches, such as the Evite site.
Scott said he was notified by Troy about the CafePress.com data leak about two weeks ago. At that time, it appeared that the source of the breach was the search engine WeleakInfo . Scott and his colleagues began investigating the case further to identify the vulnerable database that exposed the data of millions of CafePress customers.
According to another investigation, a vulnerable CafePress database containing approximately 493,000 accountswas found for sale on hacking forums. However, it is not yet certain that this is the same breach incident.
According to “Have I Been Pwned?”, CafePress was hacked in February 2019, exposing the personal information of 23,205,290 users. The compromised data includes email, names, passwords, phone numbers, and home addresses.
Scott also said that half of the compromised passwords were encoded with the base64 SHA1 algorithm, which is very weak by today's standards. Other users who logged in via Facebook and Amazon did not have compromised passwords.
CafePress has not officially announced the breach, but users are being prompted to reset passwords when they try to log in to the site, which suggests something is probably wrong.

Password resets are not enough
When a data breach becomes known, companies should inform usersso they can take appropriate protective measures.
Yet once again, in just a week, a company has decided that resetting a password is the first step in exposing a breach. A few days ago, StockX followed suit. Now, CafePress has followed suit.
Password reset notifications should be made at the same time as are notified of the breach.
