Investigation · Employee HR Data

JCPenney Data Breach Investigation

Hall Attorneys is evaluating potential claims for current and former JCPenney and associated-brand employees after a reported Oracle PeopleSoft breach involving 368,418 indexed accounts.

Verified indexed count
368,418

unique email addresses listed by HIBP

Reported breach date
June 12, 2026

date assigned by HIBP

Primary group
Employees

current and former workers in reported HR records

Answer at a glance

What happened in the JCPenney data breach?

Have I Been Pwned says JCPenney and associated brands were targeted in a June 2026 ShinyHunters pay-or-leak campaign and that data obtained through exploitation of an Oracle PeopleSoft zero-day was later published publicly.

The exposed records reportedly came primarily from internal HR systems and concerned current and former employees. HIBP lists 368,418 unique corporate and personal email addresses.

At least one putative class action, Wu v. Catalyst Brands LLC et al., was filed by other counsel on June 17, 2026. This Hall Attorneys page concerns the firm's own investigation and does not imply that Hall Attorneys filed or appears in that case.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. PeopleSoft exploitation observed

    Mandiant observed activity aligned with CVE-2026-35273 before Oracle's advisory, making the vulnerability a zero-day during the observed campaign.

  2. JCPenney breach date and extortion claim

    HIBP assigns June 12 as the breach date. Contemporary reporting says JCPenney and Catalyst Brands learned of the incident on or about that date.

  3. Separate lawsuit filed

    Wu v. Catalyst Brands LLC et al., No. 4:26-cv-00668, was filed in the Eastern District of Texas by counsel not affiliated with this page.

  4. Breach added to Have I Been Pwned

    HIBP added a verified entry listing 368,418 unique email addresses and eight compromised data categories.

Reported data categories

What information was involved?

HIBP describes internal HR records for current and former workers. The reported combination of identity, contact, and employment data can support convincing impersonation and identity-fraud attempts.

Important distinction

HIBP's 368,418 figure counts unique email addresses. The indexed description says records include Social Security numbers, but the HIBP category label groups those values under government-issued IDs.

Identity details
Names, dates of birth, and Social Security numbers
Contact information
Corporate and personal emails, phone numbers, and home addresses
Employment information
Job titles and internal HR records
Account and ID data
Usernames and other government-issued IDs

Who may want to contact us

Current and former JCPenney and associated-brand employees

The reported records are primarily employee HR data. The investigation focuses on workers and former workers whose personal information may have been retained in affected PeopleSoft systems.

Current or former JCPenney employees whose corporate or personal email appears in the HIBP entry

Current or former workers for associated Catalyst Brands whose HR records may have been involved

People who received an incident notice or identity-monitoring offer

Workers experiencing payroll-themed phishing, tax fraud, identity theft, account misuse, financial loss, monitoring costs, or lost time

What to preserve

Keep employment records, tax documents, and evidence of misuse

Preserve relevant records, but do not send passwords, complete bank-account numbers, Social Security numbers, tax forms, government identification, or unredacted credit reports through ordinary website forms.

Notices and monitoring offers

Keep the complete JCPenney or Catalyst Brands notice, envelope, email, enrollment instructions, deadline, and any later updates.

Relationship records

Preserve records showing your current or former employment with JCPenney or an associated brand, including dated account, enrollment, employment, alumni, transaction, or correspondence records.

Information held about you

Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.

Suspicious communications

Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.

Credit and account records

Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.

Time, expenses, and harm

Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is reviewing the reported PeopleSoft exploitation, the HR data involved, notice and monitoring offered to workers, retention of former-worker information, and concrete harms.

  1. Which JCPenney and Catalyst Brands PeopleSoft systems and associated brands were affected
  2. When unauthorized access began and ended and when the companies detected it
  3. How many distinct current employees, former employees, dependents, or beneficiaries were affected
  4. Which HR, payroll, tax, banking, identity, and contact fields were associated with each person
  5. How long former-worker records were retained and whether retention was necessary
  6. Whether affected workers experienced targeted phishing, tax or identity fraud, financial loss, monitoring costs, or time loss

Public records reviewed

Sources for the JCPenney incident

The sources below distinguish HIBP's verified dataset description, the technical PeopleSoft campaign record, and a separate lawsuit filed by other counsel.

Have I Been Pwned ·

JCPenney Data Breach

Lists 368,418 unique email addresses, eight compromised data categories, the reported PeopleSoft access path, and the public release.

Read source: JCPenney Data Breach

Oracle ·

Security Alert Advisory — CVE-2026-35273

Oracle says the PeopleSoft PeopleTools vulnerability is remotely exploitable without authentication, may allow remote code execution, and affects supported versions 8.61 and 8.62.

Read source: Security Alert Advisory — CVE-2026-35273

Contact the firm

Were you employed by JCPenney or an associated brand?

Contact Hall Attorneys with your general employment dates and brand, whether you received notice, and a summary of suspicious activity or loss. Do not include passwords, Social Security numbers, bank details, tax forms, or identification documents in an initial message.

Contact Hall Attorneys

Frequently asked questions

JCPenney breach FAQ

Did Hall Attorneys file the JCPenney lawsuit?

No. Public dockets show that Wu v. Catalyst Brands LLC et al. was filed by other counsel. Hall Attorneys is separately investigating potential claims.

How many JCPenney accounts were affected?

Have I Been Pwned lists 368,418 unique email addresses. That figure does not necessarily equal the number of distinct people.

Who was reportedly affected?

HIBP says the records primarily related to internal HR systems and impacted current and former employees of JCPenney and associated brands.

What information was reportedly exposed?

Reported data includes names, dates of birth, Social Security numbers, corporate and personal emails, phone numbers, home addresses, job titles, usernames, and other government-issued IDs.

Was this connected to Oracle PeopleSoft?

HIBP reports that the data was obtained through exploitation of a critical Oracle PeopleSoft zero-day vulnerability. Oracle and Mandiant separately documented CVE-2026-35273 and the broader campaign.

Attorney Advertising

Hall Attorneys is not affiliated with JCPenney or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.