Morningstar JCPenney and Catalyst Brands Data Breach Exposes Sensitive Customer Information
Article Content
- •JCPenney and Catalyst Brands experienced a significant data breach on June 12, 2026.
- •The breach involved a cybercrime group called ShinyHunters, which threatened to publish stolen data.
- •Sensitive information exposed includes Social Security numbers and W-2 tax forms.
On June 12, 2026, JCPenney and Catalyst Brands reported a data breach involving a cybercrime group known as ShinyHunters. The breach potentially exposed sensitive personal information, including Social Security numbers, dates of birth, W-2 tax forms, and driver's licenses. Edelson Lechtzin LLP has initiated an investigation into the breach and is offering free case evaluations for affected individuals. Those impacted may face increased risks of identity theft and fraud. The law firm is considering a class action lawsuit to address the claims of individuals whose data was compromised. Customers are advised to monitor their accounts and consider placing fraud alerts. The breach highlights ongoing vulnerabilities in data security for major retailers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ShinyHunters and Catalyst Brands in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…