HOT TOPIC
bd_f10f481778c00ae8 · schema v1 · pii pii-v1
Full breach record for HOT TOPIC →4 incidents on fileHot Topic, Inc. notified consumers of a data security incident involving unauthorized parties launching automated credential stuffing attacks against its website and mobile application between February 7 and June 21, 2023. The attackers used valid account credentials obtained from an unknown third-party source. Potentially accessed information included name, email address, order history, phone number, birth month/day, and mailing address. Only the last four digits of saved payment cards were potentially visible. Hot Topic engaged cybersecurity experts, deployed bot protection, and urged customers to reset passwords.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 7, 2023
Begins
Jul 31, 2023
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Oregon State AGbd_abcff497b5ca93712023-07-31Verified
- Washington State AGbd_a0d22601b4e051cd2023-07-28 · +3dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.