logo

Retail chain Hot Topic hit by new credential stuffing attacks

ID: f8c458f4-6b44-58a8-aa79-4e9ce7a81ca8

STIX ID: report--f8c458f4-6b44-58a8-aa79-4e9ce7a81ca8

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-03-28

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Hot Topic disclosed two waves of credential-stuffing attacks in November 2023 targeting Hot Topic Rewards accounts using credential lists from an unknown source; the incidents may have exposed customers' personal information and the last four digits of payment cards. The retailer engaged external cybersecurity experts, implemented bot-protection measures, and required notified customers to reset passwords, while investigators were unable to determine precisely which accounts, if any, were accessed by unauthorized parties.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.