HOT TOPIC
bd_f862836a1959a255 · schema v1 · pii pii-v1
Full breach record for HOT TOPIC →4 incidents on fileHot Topic, Inc. notified Washington AG of unauthorized access to Hot Topic Rewards accounts via credential stuffing using valid credentials from a third-party source. Incident occurred Nov 18-25, 2023. 3,655 Washington residents affected. Data potentially exposed: names, emails, order history, phone numbers, birth dates, addresses. No payment card full numbers exposed. Bot protection and password resets implemented.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 18, 2023
Begins
Nov 18, 2023
Discovered
Mar 28, 2024
Filed
vs. sector median
+11 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_f2c74f7617c5eb212024-03-28Verified
- Oregon State AGbd_33fdb7c98192ec732024-03-29 · +1dCandidate
- Illinois State AGbd_d7d4d27d0a0a53542024-03-01 · +27dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Mar 1 (IL), last Mar 29 (OR) — a 28-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.