Skip to main content
Breach Signal

Breach report

Retail

Hot Topic

HIBP notifies 57 million people of Hot Topic data breach

A hacker claimed to have stolen 350 million customer records from Hot Topic and sister brands Box Lunch and Torrid; breach notification service Have I Been Pwned verified about 57 million unique accounts in the leaked data.

Reported by BleepingComputer

Records exposed

56.9M

About 57 million accounts (hacker claimed 350 million records)

Scale vs. largest on file

When
2024
How they got in
Infostealer-stolen credentials to a cloud data platform
Sector
Retail

In October 2024, a threat actor using the name Satanic began advertising a database on a hacking forum that it said held 350 million customer records from mall retailer Hot Topic and its affiliated brands Box Lunch and Torrid. The seller asked $20,000 for the data and reportedly sought a larger payment from Hot Topic to take the listing down, later cutting the price as buyers failed to materialize. The seller said the theft took place in mid-October and covered customer data going back more than a decade.

On November 11, 2024, breach notification service Have I Been Pwned said it had processed the dataset and found 56,904,909 accounts, far fewer than the hacker's headline figure but still enough to make it one of the largest retail breaches of the year. Analysts who examined the files said they contained full names, email addresses, dates of birth, phone numbers, physical addresses, purchase histories and partial card details. A subset also included what appeared to be millions of card numbers protected with weak encryption.

Threat intelligence firm Hudson Rock reported that the intrusion likely began with infostealer malware on the computer of a person with access to Hot Topic's systems. The malware captured login credentials for cloud services the retailer used to consolidate and analyze customer data, and those credentials were then used to pull records in bulk. The pattern closely mirrored the Snowflake-related thefts that hit Ticketmaster, Advance Auto Parts and others earlier in 2024, in which attackers used stolen passwords against accounts without multifactor authentication.

Hot Topic did not publicly comment on the claims as they spread, drawing criticism from security researchers who said customers were left to learn about the incident from third parties. Class action lawsuits were filed in the weeks that followed, alleging the company failed to protect customer data and to notify affected shoppers promptly. The gap between the hacker's 350 million figure and the verified count also illustrated how breach sellers inflate numbers to attract buyers and press.

The Hot Topic incident underscored how infostealer infections have become a leading entry point for large data thefts: a single compromised device can yield credentials to cloud platforms holding years of customer records. For retailers, the lessons were to enforce multifactor authentication on every cloud account, monitor for leaked credentials and limit bulk data exports. For consumers, the exposure of birthdates, addresses and purchase histories raised the risk of convincing phishing and identity fraud.

More from the wire

More in Retail.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.