Hot Topic
ent_c3976615bbff540db7ae4f88
Disclosures
8
State AG · 5 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
157,810
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Hot Topic
- Normalized
- hot topic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- ⛰️New Hampshire State AGas victim2024-10-21
State AG breach notification filed by Hot Topic in New Hampshire on October 21, 2024. The source attachment was empty, preventing extraction of incident details, dates, or data types.
- 🏎️Indiana State AGas victim2024-10-14
Hot Topic Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-03 and was reported on 2024-10-14. 11 Indiana residents were affected.
- 🦫Oregon State AGas victim2024-03-29
Hot Topic, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-03-29. The breach occurred during 11/18/2023 - 11/19/2023, 11/25/2023 - 11/25/2023. The breach was discovered on 11/18/202311/25/2023. 157,810 individuals were affected. Notice was sent on 3/29/2024.
- 🐻California State AGas victim2024-03-28
Hot Topic, Inc. experienced a credential stuffing attack between November 18-19 and November 25, 2023, where unauthorized parties used valid account credentials obtained from a third-party source to access Hot Topic Rewards accounts. Affected data may include name, email, order history, phone number, birth month/day, and mailing address. Last four digits of saved payment cards were potentially visible. No evidence of data compromise was found, but customers were notified out of caution. Bot protection was deployed and passwords reset.
- 🌲Washington State AGas victim2024-03-28
Hot Topic, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-11-18 and filed notice on 2024-03-28. 3,655 Washington residents were affected. 131 days elapsed between awareness and notification. 0 days to identify the breach. 7 days to contain the breach.
- 🦫Oregon State AGas victim2023-07-31
Hot Topic, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-31. The breach occurred during 2/7/2023 - 2/7/2023, 3/11/2023 - 3/11/2023, 5/18/2023 - 5/21/2023, 5/27/2023 - 5/28/2023, 6/18/2023 - 6/21/2023. The breach was discovered on 2/7/20233/11/20235/18/20235/27/20236/18/2023. 129,962 individuals were affected. Notice was sent on 7/31/2023.
- 🐻California State AGas victim2023-07-31
Hot Topic, Inc. notified consumers of a data security incident involving unauthorized parties launching automated credential stuffing attacks against its website and mobile application between February 7 and June 21, 2023. The attackers used valid account credentials obtained from an unknown third-party source. Potentially accessed information included name, email address, order history, phone number, birth month/day, and mailing address. Only the last four digits of saved payment cards were potentially visible. Hot Topic engaged cybersecurity experts, deployed bot protection, and urged customers to reset passwords.
- 🌲Washington State AGas victim2023-07-28
Hot Topic, Inc., a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2023-02-07 and filed notice on 2023-07-28. 2,348 Washington residents were affected. 171 days elapsed between awareness and notification. 0 days to identify the breach.