Hot Topic hit by wave of cyber attacks

The series of attacks took place between February and June of this year

Add bookmark
A Hot Topic storefront

Retail chain company, Hot Topic, has reported that it was the victim of a series of credential stuffing attacks.

Hot Topic alerted its customers to the cyber attack in a data breach notice filed on August 1. According to the brand, cyber attacks were discovered after “suspicious login activity” was registered on its rewards platform. Said attacks took place between February 7 and June 21, 2023, and may have allowed the malicious actors responsible to access sensitive customer information. 

The hackers gained unauthorized access to Hot Topic’s Rewards platform multiple times via stolen credentials. This allowed them to potentially steal customer information, including customer name,  mailing address, date of birth, phone number and order history. Partial payment card information (the last four digits of the payment card) may have been accessed if victims had their payment card details saved to their account.

Following an investigation into the data breach, Hot Topic was able to ascertain that legitimate credentials were used in the attack, but that these credentials were obtained from an “unknown third-party source”, and not Hot Topic itself.

Hot Topic assured customers that it has launched a further investigation into the cyber attacks, as well as taking "specific steps to safeguard [its] website and mobile application from automated ‘credential stuffing’ attacks" to prevent further cyber security incidents. 

Credential stuffing attacks see malicious actors use login information stolen during data breaches to gain access to other accounts belonging to victims. They do this by using automated systems to “stuff” the credentials into online sites with the hope that victims have resused passwords across multiple sites.  

If a password has been reused, this will allow them to access the account, meanong they are able to steal further data, including personal ID numbers, payment information or authorization controls and corporate data. This data can then be sold on to other malicious actors.  

Hot Topic urged customers to reset their account password, and to use a strong and unique password, as this can prevent crednetial stuffing attempts from being successful. 


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended