Security News > 2023 > August > Retail chain Hot Topic discloses wave of credential-stuffing attacks

Retail chain Hot Topic discloses wave of credential-stuffing attacks
2023-08-01 15:02

American apparel retailer Hot Topic is notifying customers about multiple cyberattacks between February 7 and June 21 that resulted in exposing sensitive information to hackers.

Hot Topic is a retail chain specialized in counter-culture clothing and accessories, and licensed music, that has 675 stores across the U.S. It also operates an online shop with nearly 10 million visitors every month, according to data from SimilarWeb.

"We recently identified suspicious login activity to certain Hot Topic Rewards accounts," reads the notice.

The company says that the investigation determined that Hot Topic was not the source of the credentials but it could also not find the source.

As part of the security measures implemented after the attacks, Hot Topic added "Specific steps to safeguard our website and mobile application from" credential-stuffing attacks.

If you are a Hot Topic customer, resetting your account credentials on other platforms where you might be using the same credentials would be wise.


News URL

https://www.bleepingcomputer.com/news/security/retail-chain-hot-topic-discloses-wave-of-credential-stuffing-attacks/