DisclosureLens
HackingRetail & ConsumerRetailStolen CredentialsCustomer Data InvolvedMulti-Stage ChainAuthenticationIdentity (basic)PIIMediumContained

HOT TOPIC

bd_a0d22601b4e051cd · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 7, 2023

Filed

Jul 28, 2023

To disclose

24 weeks

Affected

2,348state residents only

Linked

3 filings

Confidence

68%
Full breach record for HOT TOPIC4 incidents on file

Hot Topic, Inc. notified Washington AG of a data breach involving credential stuffing attacks on Hot Topic Rewards accounts. Unauthorized parties used stolen credentials to access customer data including names, emails, order history, and addresses. 2,348 Washington residents were affected. Notifications sent July 31, 2023.

Washington clock WA AG >90d24 weeks discovery → filing
occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.

Incident timeline

discovery → filing · 24 weeks / 171 days

Feb 7, 2023

Begins

Feb 7, 2023

Discovered

Jul 28, 2023

Filed

vs. sector median

+17 wks slower

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Washington State AGJul 28 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.