HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICBEHAVIORFINANCIAL_ACCOUNTLowContained
Hot Topic
bd_f2c74f7617c5eb21 · schema v1 · pii pii-v1
Full breach record for Hot Topic →Hot Topic, Inc. experienced a credential stuffing attack between November 18-19 and November 25, 2023, where unauthorized parties used valid account credentials obtained from a third-party source to access Hot Topic Rewards accounts. Affected data may include name, email, order history, phone number, birth month/day, and mailing address. Last four digits of saved payment cards were potentially visible. No evidence of data compromise was found, but customers were notified out of caution. Bot protection was deployed and passwords reset.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_f862836a1959a255Washington State AGfiled 2024-03-28Verified
- bd_33fdb7c98192ec73Oregon State AGfiled 2024-03-29(1d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-583177
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 28, 2024
- Raw hash
- 587e866cbe1683c06c74c2712308d818bc483054d155ca10eca142fe7cda9997
Reporting entity
- Name
- Hot Topicnorm: hot topic
Victim entity
- Name
- Hot Topicnorm: hot topic
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICBEHAVIORFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1110 Brute Force
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.