Security

Cyber-crime

'Satanic' data thief claims to have slipped into 350M Hot Topic shoppers info

We know where you got your skinny jeans - big deal


A data thief calling themselves Satanic claims to have purloined the records of around 350 million customers of fashion retailer Hot Topic.

Israeli security shop Hudson Rock reports that the criminal says they have hacked the loyalty account of the fashion megachain, harvesting 350 million customers' PII, including names, emails, physical addresses, and dates of birth.

It appears that financial details have at least been somewhat protected, with the evil one saying it has the last four digits of customers’ credit cards, card types, hashed expiration dates, and account holder names, but the criminal claims to have billions of payment details.

That said, they are asking for $20,000 for the database, which is very low but understandable given the paucity of actionable information stolen - the wages of sin are scarce at this level. Satanic also offered Hot Topic the chance to pay $100,000 to remove the sale listing.

It appears that the leak possibly came from an employee at Robling, a retail analytics business. Hudson Rock reports that the data most likely came from the staffer who picked up a malware infection in September, and the shoplifted data contained 240 credentials.

"While this evidence alone doesn’t conclusively prove how these companies were hacked, Hudson Rock’s researchers reached out to 'Satanic' for more details," the security biz said.

"'Satanic' first claimed that the breach originated from an Infostealer log. They provided a username matching the one found on the computer our researchers were investigating."

While the scale of the data theft is on large size, its impact is likely to be slight. Sure, no one likes having even basic information stolen, but outside of a fashion-related phishing attempt, the database is going to be of limited value.

However, Hudson says that Satanic's reputation as a data thief is solid and it makes a fairly decent living (in financial terms at least) from selling such data.

Hot Topic was unavailable for comment at the time of going to press. ®

Send us news
2 Comments

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

Release the Kraken!

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Merde! Macron's bodyguards reveal his location by sharing Strava data

It's not just the French president, Biden and Putin also reportedly trackable

Brazen crims selling stolen credit cards on Meta's Threads

The platform 'continues to take action' against illegal posts, we're told

AWS Cloud Development Kit flaw exposed accounts to full takeover

Remember Bucket Monopoly? Yeah, it gets worse