HOT TOPIC
ent_c3976615bbff540db7ae4f88
Disclosures
10
State AG · 6 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
157,810
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- HOT TOPIC
- Normalized
- hot topic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- New Hampshire State AGas victim2024-10-21
Hot Topic, Inc. notified the NH AG of suspicious login activity on July 3 and 6, 2024 involving valid credentials from a third-party source. The incident was contained early. Three NH residents were notified on Oct 14, 2024. No unauthorized access was confirmed.
- Indiana State AGas victim2024-10-14
Hot Topic Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2024-07-03 and was reported on 2024-10-14. 11 Indiana residents were affected.
- Oregon State AGas victim2024-03-29
Hot Topic, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-03-29. The breach occurred during 11/18/2023 - 11/19/2023, 11/25/2023 - 11/25/2023. The breach was discovered on 11/18/202311/25/2023. 157,810 individuals were affected. Notice was sent on 3/29/2024.
- California State AGas victim2024-03-28
Hot Topic, Inc. experienced a credential stuffing attack between November 18-19 and November 25, 2023, where unauthorized parties used valid account credentials obtained from a third-party source to access Hot Topic Rewards accounts. Affected data may include name, email, order history, phone number, birth month/day, and mailing address. Last four digits of saved payment cards were potentially visible. No evidence of data compromise was found, but customers were notified out of caution. Bot protection was deployed and passwords reset.
- Washington State AGas victim2024-03-28
Hot Topic, Inc. notified Washington AG of unauthorized access to Hot Topic Rewards accounts via credential stuffing using valid credentials from a third-party source. Incident occurred Nov 18-25, 2023. 3,655 Washington residents affected. Data potentially exposed: names, emails, order history, phone numbers, birth dates, addresses. No payment card full numbers exposed. Bot protection and password resets implemented.
- Illinois State AGas victim2024-03-01
HOT TOPIC, INC filed a data-breach notice with the Illinois Attorney General in March 2024 (case 24-03-102). The register records the breach as discovered on November 18, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Oregon State AGas victim2023-07-31
Hot Topic, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2023-07-31. The breach occurred during 2/7/2023 - 2/7/2023, 3/11/2023 - 3/11/2023, 5/18/2023 - 5/21/2023, 5/27/2023 - 5/28/2023, 6/18/2023 - 6/21/2023. The breach was discovered on 2/7/20233/11/20235/18/20235/27/20236/18/2023. 129,962 individuals were affected. Notice was sent on 7/31/2023.
- California State AGas victim2023-07-31
Hot Topic, Inc. notified consumers of a data security incident involving unauthorized parties launching automated credential stuffing attacks against its website and mobile application between February 7 and June 21, 2023. The attackers used valid account credentials obtained from an unknown third-party source. Potentially accessed information included name, email address, order history, phone number, birth month/day, and mailing address. Only the last four digits of saved payment cards were potentially visible. Hot Topic engaged cybersecurity experts, deployed bot protection, and urged customers to reset passwords.
- Washington State AGas victim2023-07-28
Hot Topic, Inc. notified Washington AG of a data breach involving credential stuffing attacks on Hot Topic Rewards accounts. Unauthorized parties used stolen credentials to access customer data including names, emails, order history, and addresses. 2,348 Washington residents were affected. Notifications sent July 31, 2023.
- Illinois State AGas victim2023-01-01
HOT TOPIC filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-496). The register records the breach as discovered on February 7, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.