FTC settlement requires CafePress owners to pay $500,000 to victims of 2019 data breach
Full article573 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The commission accused the company of covering up the hack.
The Federal Trade Commission is requiring customized merchandise platform CafePress to pay victims of a 2019 data breach $500,000 in redress.
The regulator accused the company of inadequately securing user data and ignoring known security threats, failures which led to a February 2019 breach in which a hacker accessed millions of email addresses and passwords. The hacker used the stolen credentials to find 180,000 unencrypted Social Security numbers. Some of the information was later found on the dark web.
According to the complaint, the company quietly patched the vulnerability but did not notify customers until a month after the breach was publicly reported in August 2019. The company continued to allow consumers to use information exposed in the hack to login to user accounts.
The 2019 breach was not the first cybersecurity incident the company hid from customers, the FTC alleges. In January 2018, CafePress charged shopkeepers whose accounts the company determined to be compromised $25 to close their accounts.
“The company also experienced several malware infections to its network prior to the 2019 hack but failed to investigate the source of such attacks,” according to the complaint.
“CafePress employed careless security practices and concealed multiple breaches from consumers,” Samuel Levine, director of the FTC’s Bureau of Consumer Protection, said Tuesday in a news release announcing the fine. “These orders dial up accountability for lax security practices, requiring redress for small businesses that were harmed, and specific controls, like multi-factor authentication, to better safeguard personal information.”
Terms of the settlement include that the company replace inadequate authentication measures such as security questions with multi-factor authentication. The complaint also alleges CafePress “misled users by using consumer email addresses for marketing despite its promises that such information would only be used to fulfill orders consumers had placed.”
The settlement names Residual Pumpkin Entity, LLC, the former owner of CafePress, and PlanetArt, LLC, which bought CafePress in 2020.
Seven states attorneys general led by New York reached a $2 million agreement with CafePress in 2020 over the 2018 breach. The agreement included voluntary compliance with new security measures.
CafePress did not immediately respond to a request for comment.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ftc-cafepress-breach-settlement/