← JCPenney

2026 JCPenney — ShinyHunters HR extortion; ~368K staff emails leaked (unverified)

2026 368.0K records affected Share on X

Data compromised

Actor-claimed and allegedly leaked HR corpus: ~368,000 email addresses, names, SSNs, W-2/payroll records, and government ID scans for current and former staff—unverified; Catalyst/Authentic Brands sister retailers also named

Technical writeup

Unverified ShinyHunters extortion claim — June 2026. On June 12, 2026 ShinyHunters listed JCPenney and several Catalyst Brands / Authentic Brands Group retail subsidiaries on its leak site, claiming hundreds of thousands of records including Social Security numbers, dates of birth, W-2 tax forms, payroll data, and scans of government-issued IDs, with a June 15 contact deadline before public release. Cybernews and Money.com reported June 12–17 that JCPenney had not confirmed the incident at initial trade-press updates; attorneys and class-action investigators opened probes citing the Ransomware.live listing. Breach-intelligence reporting describes an allegedly leaked employee HR corpus of roughly 368,000 email addresses affecting current and former staff, alongside names and SSNs—indexed as unverified; JCPenney had not confirmed at indexing time. Trade press links the wider ShinyHunters PeopleSoft activity to Oracle emergency advisory CVE-2026-35273 (June 2026).

Root cause

ShinyHunters extortion listing June 12, 2026; possible Oracle PeopleSoft CVE-2026-35273 campaign vector cited in trade press

References