Data breach
Hot Topic
- Records
- 384,099,181
- Breach date
- 18 November 2023Estimated
- Added
- 24 October 2024
What was exposed
7 types of data · 2 more reported · 1 puts you at serious risk
- Email addresses54,488,321
- Card numbers24,989,090
- Names24,848,161
- Phone numbers24,706,012
- Home addresses9,852,621
- Job titles344,182
- Employment8,645
- Purchase historyReported, not counted
- Dates of birthReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Hot Topic, the mall retailer known for band apparel and pop culture merchandise, was hit by automated credential-stuffing attacks in November 2023 that exposed customer account data, and our investigation team has indexed a dataset tied to the incident containing more than 384 million rows. The attacks targeted Hot Topic Rewards accounts using login credentials obtained from an unknown third-party source, meaning the credentials did not come from Hot Topic itself. The company disclosed the incident in breach notification letters and a filing with the California Attorney General, stating it could not determine which logins were made by attackers and which were legitimate customer sign-ins. Our investigation team estimates the attack date as November 18, 2023, and indexes the dataset at 384,099,181 rows, including roughly 54.5 million email addresses and about 24.9 million credit card entries. No threat actor has publicly claimed this listing.
Breach Timeline
February 7 to June 21, 2023: Hot Topic later disclosed that attackers struck its Rewards platform in multiple waves on February 7, March 11, May 19-21, May 27-28, and June 18-21, 2023, using valid credentials from an unknown source.
November 18-19 and November 25, 2023: A second series of automated credential-stuffing attacks hit the Hot Topic website and mobile app, according to the company's breach notice.
Late March 2024: BleepingComputer reported the disclosure of the November attacks, after notification letters went to potentially affected customers.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses (about 54.5 million), phone numbers (about 24.7 million), names (about 24.8 million), credit card entries (about 24.9 million), home addresses (about 9.9 million), and smaller volumes of job-related fields, including roughly 344,000 job titles.
Hot Topic's own breach notice, filed with the California Attorney General, lists additional account details that intruders could have viewed inside Rewards accounts: order history, the month and day of a customer's birth, and the last four digits of any saved payment card. The notice does not list full card numbers, Social Security numbers, or passwords as exposed in the November incident.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Credential-stuffing attacks succeed mainly because people reuse passwords across sites. Anyone whose Hot Topic Rewards account was reached could face unauthorized purchases or account takeovers if the same email and password pair was used elsewhere.
Exposed names, emails, phone numbers, addresses, and birth month and day are also useful raw material for phishing. Criminals can craft convincing messages that reference real orders or loyalty accounts to trick recipients into handing over passwords or payment details. Partial card data, limited to the last four digits, is not enough to make fraudulent charges on its own, but it can add credibility to scams when combined with other personal details.
Because the company said it could not tell unauthorized logins apart from legitimate ones, some affected customers may not know their accounts were touched.
What Is Hot Topic Doing in Response?
According to the company's notice, Hot Topic detected the suspicious login activity, began an investigation, and worked with outside cybersecurity experts. It deployed bot protection software designed to stop automated credential-stuffing attacks on its website and mobile app. The company also required affected customers to set new passwords, which would make stolen credentials useless on Hot Topic platforms. Hot Topic stated it had no evidence that personal information was actually compromised or accessed, but notified customers out of caution.
What Should You Do If You Were Affected?
Change your Hot Topic Rewards password if you have not already, and choose one you do not use anywhere else.
If you reused that password on other accounts, change it there too, and turn on multi-factor authentication where it is offered.
Watch statements on any payment card saved to your Rewards account for charges you do not recognize.
Be cautious with unexpected emails or texts that mention Hot Topic, orders, or loyalty points, and avoid clicking links or sharing credentials in response.
You can review monitoring guidance from the Federal Trade Commission at identitytheft.gov if you notice signs of misuse of your personal information.
In the news
- Hot Topic Notice of Data Breach, California Attorney Generaloag.ca.gov (opens in a new tab)
- BleepingComputer: Retail chain Hot Topic hit by new credential stuffing attacksbleepingcomputer.com (opens in a new tab)
- BleepingComputer: Retail chain Hot Topic discloses wave of credential-stuffing attacksbleepingcomputer.com (opens in a new tab)
