Skip to main content
Back to overview
High

BoxLunch Customer Data Exposed in Hot Topic Group Security Incident

Scam of the day – November 18, 2024 – Massive Data Breach at Hot Topic by Steven Weisman, Esq.

Key points

  • Part of Hot Topic group breach
  • Nearly 57 million customer records impacted across brands
  • Exposed personal information

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Nov 15, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

BoxlunchData DisclosureHot Topic Group Security IncidentScam of theHot TopicSteven WeismanEsqNovFashionAmong the

Quick context

Questions about this signal

What happened in this signal?

Scam of the day – November 18, 2024 – Massive Data Breach at Hot Topic by Steven Weisman, Esq. | Nov 17, 2024 | Scam of the day Fashion retailer Hot Topic has suffered a massive data breach affecting 57 million of its customers. Among the data stolen was email addresses, home addresses, phone numbers, purchases, birth dates and partial credit card data, all of which can be used by scammers for identity theft purposes. The data breach occurred on October 19th and the hacker, who uses the name “Satanic” already has posted some of the information on the Dark Web site BreachForums, one of the sites used by cybercriminals to buy and sell goods and services. As of the writing of this Scam of the day, Hot Topics has not yet confirmed the data breach nor notified its customers or governmental officials of the data breach. Victims of this data breach should freeze their credit if they have not already done so. Freezing your credit is actually something everyone should do. It is free and easy to do. In addition, it protects you from someone using your identity to obtain loans or make large purchases even if they have your Social Security number. If you have not already done so, put a credit freeze on your credit reports at all of the major credit reporting agencies. Here are links to each of them with instructions about how to get a credit freeze: If you are not a subscriber to Scamicide.com and would like to receive daily emails with the Scam of the day, all you need to do is sign up for free using this link. https://scamicide.com/scam-of-the-day/ Every year, countless emails hit our inboxes telling us that our personal information was accessed, shared, or stolen in a data breach. In many cases, there is little we can do. Most of us can assume that at least our phone numbers, emails, addresses, credit card numbers, and social security numbers are all available somewhere on the internet. But some of these data breaches are more noteworthy than others, because they include novel information about us, are the result of particularly noteworthy security flaws, or are just so massive they’re impossible to ignore. For that reason, we are introducing the Breachies, a series of tongue-in-cheek “awards” for some of the most egregious data breaches of the year. If these companies practiced a privacy first approach and focused on data minimization, only collecting and storing what they absolutely need to provide the services they promise, many data breaches would be far less harmful to the victims. But instead, companies gobble up as much as they can, store it for as long as possible, and inevitably at some point someone decides to poke in and steal that data. Once all that personal data is stolen, it can be used against the breach victims for identity theft , ransomware attacks , and to send unwanted spam . The risk of these attacks isn’t just a minor annoyance: research shows it can cause psychological injury , including anxiety, depression, and PTSD. To avoid these attacks, breach victims must spend time and money to freeze and unfreeze their credit reports, to monitor their credit reports, and to obtain identity theft prevention services . This year we’ve got some real stinkers, ranging from private health information to—you guessed it—credit cards and social security numbers. The Just Stop Using Tracking Tech Award: Kaiser Permanente The Most Impactful Data Breach for ’ 90s Kids Award: Hot Topic The I Didn’t Even Know You Had My Information Award: Evolve Bank The Why We’re Still Stuck on Unique Passwords Award: Roku The Listen, Security Researchers are Trying to Help Award: City of Columbus The Have I Been Pwned ? Award: Spoutible The Reporting’s All Over the Place Award: National Public Data The Biggest Health Breach We’ve Ever Seen Award: Change Health The There’s No Such Thing As Backdoors for Only “Good Guys” Award: Salt Typhoon Breach of the Year (of the Decade?) : Snowflake In one of the year's most preventable breaches, the healthcare company Kaiser Permanente exposed 13 million patients’ information via tracking code embedded in its website and app. This tracking code transmitted potentially sensitive medical information to Google, Microsoft, and X (formerly known as Twitter). The exposed information included patients’ names, terms they searched in Kaiser’s Health Encyclopedia, and how they navigated within and interacted with Kaiser’s website or app. The most troubling aspect of this breach is that medical information was exposed not by a sophisticated hack, but through widely used tracking technologies that Kaiser voluntarily placed on its website. Kaiser has since removed the problematic code, but tracking technologies are rampant across the internet and on other healthcare websites. A 2024 study found tracking technologies sharing information with third parties on 96% of hospital websites. Websites usually use tracking technologies to serve targeted ads. But these same technologies give advertisers , data brokers , and law enforcement easy access to details about your online activity. While individuals can protect themselves from online tracking by using tools like EFF’s Privacy Badger , we need legislative action to make online privacy the norm for everyone. EFF advocates for a ban on online behavioral advertising to address the primary incentive for companies to use invasive tracking technology. Otherwise, we’ll continue to see companies voluntarily sharing your personal data, then apologizing when thieves inevitably exploit a vulnerability in these tracking systems. If you were in middle or high school any time in the ’ 90s you probably have strong memories of Hot Topic. Baby goths and young punk rockers alike would go to the mall, get an Orange Julius and greasy slice of Sbarro pizza, then walk over to Hot Topic to pick up edgy t-shirts and overpriced bondage pants (all the while debating who was the biggest poser and which bands were sellouts, of course).

When was this signal reported?

Shadow Tier lists Nov 15, 2024 as the signal date.

Which organization is connected to this signal?

Boxlunch is the organization connected to this public signal.

Explore Boxlunch
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence