2026 JCPenney — ShinyHunters HR extortion; ~368K staff emails leaked (unverified)
Data compromised
Actor-claimed and allegedly leaked HR corpus: ~368,000 email addresses, names, SSNs, W-2/payroll records, and government ID scans for current and former staff—unverified; Catalyst/Authentic Brands sister retailers also named
Technical writeup
Unverified ShinyHunters extortion claim — June 2026. On June 12, 2026 ShinyHunters listed JCPenney and several Catalyst Brands / Authentic Brands Group retail subsidiaries on its leak site, claiming hundreds of thousands of records including Social Security numbers, dates of birth, W-2 tax forms, payroll data, and scans of government-issued IDs, with a June 15 contact deadline before public release. Cybernews and Money.com reported June 12–17 that JCPenney had not confirmed the incident at initial trade-press updates; attorneys and class-action investigators opened probes citing the Ransomware.live listing. Breach-intelligence reporting describes an allegedly leaked employee HR corpus of roughly 368,000 email addresses affecting current and former staff, alongside names and SSNs—indexed as unverified; JCPenney had not confirmed at indexing time. Trade press links the wider ShinyHunters PeopleSoft activity to Oracle emergency advisory CVE-2026-35273 (June 2026).
Root cause
ShinyHunters extortion listing June 12, 2026; possible Oracle PeopleSoft CVE-2026-35273 campaign vector cited in trade press
References
- https://cybernews.com/security/shinyhunters-jcpenney-retail-data-leak-claim/
- https://www.ransomware.live/id/SkNQZW5uZXkgJiBzZXZlcmFsIG90aGVyIHN1YnNkaWFyaWVzIHVuZGVyIENhdGFseXN0IEJyYW5kcyAmIEF1dGhlbnRpYyBCcmFuZHMgR3JvdXBAc2hpbnlodW50ZXJz
- https://money.com/scam-alert-jcpenney-hack-shinyhunters-identity-theft/
- https://www.techrepublic.com/article/news-oracle-peoplesoft-zero-day-shinyhunters/
- https://www.classaction.org/data-breach-lawsuits/jcpenney-june-2026