Skip to main content
Federal Trade Commission · Announced 2022-06-23

Residual Pumpkin Entity, LLC (formerly CafePress), $500,000

CafePress failed to respond appropriately to a 2019 data breach, delayed notifying affected consumers until September 2019, and misrepresented the effectiveness of its password reset while stolen security-question answers still enabled account takeovers.

Case identifiers

Respondent
Residual Pumpkin Entity, LLC (formerly CafePress) (and PlanetArt, LLC)
Agency
Federal Trade Commission
Announced
2022-06-23
Monetary relief
$500,000
Case number
FTC File No. 192-3209
Statutes cited
FTC Act § 5

Key facts

  • 1

    The February 2019 breach exposed more than 20 million unencrypted email addresses and encrypted passwords, millions of names, physical addresses, security questions and answers, more than 180,000 Social Security numbers, and tens of thousands of partial payment-card records.

  • 2

    After learning of the intrusion in March 2019 and receiving a foreign-government warning in April, CafePress did not send breach notices to affected consumers until September 2019.

  • 3

    CafePress told individuals, law enforcement, and regulators that its April 15 password reset blocked unauthorized use, but until at least November 19, 2019 its site still allowed password resets using stolen security-question answers without verifying control of the email address.

  • 4

    $500,000 redress to affected consumers plus injunctive relief against successor PlanetArt.

What the order requires

Injunctive terms imposed by the Federal Trade Commission. These bind Residual Pumpkin Entity, LLC (formerly CafePress)'s data practices going forward.

  • Implementation of a comprehensive information security program.
  • Prompt notification of consumers affected by future breaches.
  • Required biennial third-party assessments.

Primary sources

Read the original government documents. These are the authoritative records, everything on this page is derived from them.

Generate requests in under 60 seconds

Generate a deletion request for $9

The FTC order binds Residual Pumpkin Entity, LLC (formerly CafePress)'s future practices, but doesn't automatically delete your existing data. State privacy law (CCPA, CPA, TDPSA, VCDPA) gives you that right. OfflistMe generates a compliant deletion email pre-addressed to Residual Pumpkin Entity, LLC (formerly CafePress)'s registered privacy contact.

FAQ

What did the FTC charge Residual Pumpkin Entity, LLC (formerly CafePress) with?+

CafePress failed to respond appropriately to a 2019 data breach, delayed notifying affected consumers until September 2019, and misrepresented the effectiveness of its password reset while stolen security-question answers still enabled account takeovers. The Federal Trade Commission cited FTC Act § 5.

How much did Residual Pumpkin Entity, LLC (formerly CafePress) pay?+

Residual Pumpkin Entity, LLC (formerly CafePress) had monetary relief of $500,000, announced on 2022-06-23. The settlement also imposed injunctive terms (see below).

Does the Residual Pumpkin Entity, LLC (formerly CafePress) settlement mean my data has been deleted?+

No, the order does not automatically delete your data. You retain full rights under state privacy law (CCPA, CPA, TDPSA, VCDPA, and others) to submit your own deletion request. OfflistMe can generate a compliant deletion email pre-addressed to the respondent’s privacy contact.

How can I read the original FTC order?+

The Federal Trade Commission press release is available at https://www.ftc.gov/news-events/news/press-releases/2022/06/ftc-takes-action-against-cafepress-data-breach-cover. The case / matter number is FTC File No. 192-3209.

Related enforcement actions

Related