JCPenney and Catalyst Brands Data Breach Exposes Sensitive Customer Information

JCPenney and Catalyst Brands Data Breach Exposes Sensitive Customer Information

First seen 18 Jun 2026, 16:44 UTC PrnewswireMorningstar 100% similarity 68.2

Article Content

Browse articles
ThreatCluster

On June 12, 2026, JCPenney and Catalyst Brands reported a data breach involving a cybercrime group known as ShinyHunters. The breach potentially exposed sensitive personal information, including Social Security numbers, dates of birth, W-2 tax forms, and driver's licenses. Edelson Lechtzin LLP has initiated an investigation into the breach and is offering free case evaluations for affected individuals. Those impacted may face increased risks of identity theft and fraud. The law firm is considering a class action lawsuit to address the claims of individuals whose data was compromised. Customers are advised to monitor their accounts and consider placing fraud alerts. The breach highlights ongoing vulnerabilities in data security for major retailers.

Key Points: • JCPenney and Catalyst Brands experienced a significant data breach on June 12, 2026. • The breach involved a cybercrime group called ShinyHunters, which threatened to publish stolen data. • Sensitive information exposed includes Social Security numbers and W-2 tax forms.

ThreatCluster AI How this analysis works

Timeline

2026-06-12
Data breach discovered by JCPenney and Catalyst Brands
The companies confirmed a breach involving a cybercrime group threatening to publish stolen records.
Morningstar
2026-06-18
Edelson Lechtzin LLP launches investigation
The law firm is investigating data privacy claims and offering free case evaluations for affected individuals.
Prnewswire

Community

Browse all →

Tracked Entities in This Story