Unverified claim — June 2026: Extortion group ShinyHunters listed JCPenney and sister retail brands under Catalyst Brands and Authentic Brands Group on its leak site June 12, claiming hundreds of thousands of HR records. BreachHistory tracks the listing at JCPenney ShinyHunters 2026 — ~368,000 staff email addresses cited in reporting; JCPenney has not confirmed.
What ShinyHunters claims
Cybernews and Money.com summarized the June 12 listing:
- Social Security numbers and dates of birth
- W-2 tax records and payroll files
- Scans of driver’s licenses and government IDs
- Other HR PII for current and former employees
ShinyHunters set a June 15, 2026 deadline before threatening public release. Subsequent breach-intelligence reporting—not yet confirmed by JCPenney—describes an allegedly leaked corpus of roughly 368,000 email addresses tied to staff HR systems. At initial Cybernews updates the group had not published samples; scope may expand if files circulate post-deadline.
Possible PeopleSoft link
TechRepublic tied the wider June 2026 ShinyHunters activity to Oracle emergency advisory CVE-2026-35273, a critical PeopleSoft flaw exploited against HR/payroll deployments. Class-action investigators are examining whether the JCPenney listing connects to that campaign—still unconfirmed.
Who may be affected
Priority risk is current and former JCPenney employees, not shoppers—though sister brands (Aéropostale, Brooks Brothers, Lucky Brand, Nautica, etc.) were named in the same ShinyHunters post. Stolen SSNs and W-2s enable tax fraud and targeted phishing that cites real salary or manager details.
What to do now
- Do not download alleged leak archives from Tor or file-sharing links.
- Place a credit freeze or fraud alert if you worked at JCPenney or an affected sister brand.
- Watch for IRS or payroll phishing citing real W-2 line items.
- Wait for official JCPenney HR or legal notices—not extortion emails.
Canonical record: JCPenney 2026 unverified claim on BreachHistory.
Sources: Cybernews, Ransomware.live, Money.com