Hot Topic
bd_f10f481778c00ae8 · schema v1 · pii pii-v1
Full breach record for Hot Topic →Hot Topic, Inc. notified consumers of a data security incident involving unauthorized parties launching automated credential stuffing attacks against its website and mobile application between February 7 and June 21, 2023. The attackers used valid account credentials obtained from an unknown third-party source. Potentially accessed information included name, email address, order history, phone number, birth month/day, and mailing address. Only the last four digits of saved payment cards were potentially visible. Hot Topic engaged cybersecurity experts, deployed bot protection, and urged customers to reset passwords.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_abcff497b5ca9371Oregon State AGfiled 2023-07-31Verified
- bd_a0d22601b4e051cdWashington State AGfiled 2023-07-28(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-571054
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2023
- Raw hash
- e93126d095511777abee16fcbb3fa639ed39d4ed2efd6c8ef3c0a9e969ea3ba7
Reporting entity
- Name
- Hot Topicnorm: hot topic
Victim entity
- Name
- Hot Topicnorm: hot topic
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.