Hot Topic breach exposed records on nearly 57 million retail customers
- Organization
- Hot Topic
- Exploit
- Third-Party Data Breach
- Industry
- Retail
In late October 2024, a threat actor using the handle "Satanic" offered a customer database on the BreachForums marketplace that was said to have been taken from the fashion retailer Hot Topic and its sister brands Torrid and BoxLunch, all owned by Sycamore Partners. The breach notification service Have I Been Pwned added the data set on November 11, 2024 after verifying 56.9 million unique email addresses.
The verified records included names, email addresses, physical addresses, phone numbers, dates of birth, genders, purchase histories and partial payment card data covering card type, expiry date and the last four digits. Satanic claimed the database held as many as 350 million user records, a figure well above what was verified, and Help Net Security reported the seller was asking $20,000 for access.
Researchers at Hudson Rock attributed the intrusion to infostealer malware that infected a computer belonging to an employee of Robling, a retail analytics vendor working with the brands. The harvested credentials were used to reach Hot Topic's Snowflake and Looker cloud environments, which were not protected by multi-factor authentication. The credential theft was dated to around September 2024 and the data access to October.
Hot Topic did not respond to press inquiries about the incident. Forbes reported that as of mid-November 2024 the company had not notified customers or filed with state attorneys general, and no company statement had been issued. It was the second breach affecting Hot Topic customers to surface in about a year.