CafePress got its consumers’ sensitive personal data, including Social Security numbers, exposed. The claim against Residual Pumpkin Entity, former owner of CafePress and PlanetArt, current owner of CafePress was filled by the Federal Trade Commission. The main issue of the claim is that the organization had failed to ensure safety of client’s personal data (including Social Security numbers), and covered up the data breach.
According to the FTC experts’ opinion, sufficient measures, required for sensitive data protection of buyers and sellers weren’t implemented, and also there wasn’t an adequate respond to some security breaches.
The FTC claims include the following:
“Stored Social Security numbers and password reset answers in clear, readable text;
Retained the data longer than was necessary;
Failed to apply readily available protections against well-known threats and adequately respond to security incidents;
Covered up a major data breach resulting from its shoddy security practices”.
According to the statement by the FTC, Residual Pumpkin must pay $500,000, which will be used to provide redress to victims of the data breaches, and comprehensive information security programs must be implemented in response for the incident.
This case illustrates the tendency, corresponding with regulations – more and more information security related acts will come into force, and regulators will monitor activities of all types of personal data operators more strictly. In case security rules are violated, impose significant fines. One of the most crucial recommendation by the FTC in this case is that there is a need for usage of “comprehensive information security programs”. This is a reasonable measure, as in case such measures aren’t implemented, we will witness plenty of other data related incidents occurrence. Our experts also argue for the necessity of implementation of a new complex approach to organization’s security, which you can find in our blog post.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!