HOT TOPIC
bd_f2c74f7617c5eb21 · schema v1 · pii pii-v1
Full breach record for HOT TOPIC →4 incidents on fileHot Topic, Inc. experienced a credential stuffing attack between November 18-19 and November 25, 2023, where unauthorized parties used valid account credentials obtained from a third-party source to access Hot Topic Rewards accounts. Affected data may include name, email, order history, phone number, birth month/day, and mailing address. Last four digits of saved payment cards were potentially visible. No evidence of data compromise was found, but customers were notified out of caution. Bot protection was deployed and passwords reset.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 18, 2023
Begins
Mar 28, 2024
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Washington State AGbd_f862836a1959a2552024-03-28Verified
- Oregon State AGbd_33fdb7c98192ec732024-03-29 · +1dCandidate
- Illinois State AGbd_d7d4d27d0a0a53542024-03-01 · +27dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Mar 1 (IL), last Mar 29 (OR) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.