Hot Topic disclosed credential stuffing attacks on Rewards accounts

Organization
Hot Topic
Exploit
Credential Compromise
Industry
Retail

Hot Topic, the U.S. apparel and accessories retailer, disclosed on August 1, 2023 that its Hot Topic Rewards accounts had been targeted in a series of automated credential stuffing attacks.

The company said attackers used valid login credentials obtained from an unknown third party source to submit large volumes of automated login requests against its website and mobile application. Hot Topic said it could not identify where those credentials originated and found no indication that its own systems were the source.

BleepingComputer reported that the attacks came in five waves: February 7, March 11, May 19 to 21, May 27 to 28, and June 18 to 21, 2023. Because the company could not reliably separate unauthorized logins from legitimate ones, it notified every customer whose account was accessed during those windows, which it described as an abundance of caution.

Information potentially exposed included names, email addresses, mailing addresses, phone numbers, dates of birth, order history and the last four digits of any payment card saved to an account. Hot Topic did not disclose how many accounts were involved.

The retailer said it engaged cybersecurity experts, deployed bot protection software on its website and app, and urged customers to reset their passwords and avoid reusing credentials. It filed a data breach notification in California, as state law requires.

Sources