Hot Topic notifies customers after November 2023 credential stuffing attacks
- Organization
- Hot Topic, Inc.
- Exploit
- Credential Compromise
- Industry
- Retail
Retailer Hot Topic began notifying customers in March 2024 that their Hot Topic Rewards accounts may have been accessed during automated credential stuffing attacks the previous November.
In the notification, the company said its website and mobile app were targeted on November 18 and 19 and again on November 25, 2023, by an attacker using valid username and password pairs obtained from an unnamed third party. Hot Topic said it was not the source of those credentials, which in this type of attack are typically taken from breaches at unrelated services and then replayed at scale against another site's login page.
Accounts that were successfully accessed would have exposed a customer's name, email address, order history, phone number, month and day of birth and mailing address, along with the last four digits of any saved payment card. Full card numbers were not held in the accounts. Hot Topic told customers it could not distinguish unauthorized logins from legitimate ones during the attack windows, so it notified everyone potentially affected as a precaution.
The company said it worked with outside cybersecurity specialists, deployed bot protection software on its website and app, and required customers who received notices to set a new password. BleepingComputer reported that the November waves followed five earlier rounds of credential stuffing against Hot Topic accounts between February and June 2023.