JCPenney / Catalyst Brands
ShinyHunters exploits Oracle PeopleSoft zero-day to steal 368,000 employee records—SSNs, W-2s, and government IDs from the American retail icon and its sister brands.
What happened?
ShinyHunters posted JCPenney to their leak site on June 12, 2026, claiming "hundreds of thousands" of records stolen and setting a June 15 deadline. The attack exploited CVE-2026-35273, a critical remote code execution vulnerability in Oracle PeopleSoft rated 9.8 on the CVSS scale. The vulnerability requires no authentication—just network access over HTTP.
JCPenney and parent company Catalyst Brands confirmed the breach affected internal HR systems. The attack was part of ShinyHunters' broader PeopleSoft campaign that hit over 100 organizations in two weeks. When the deadline passed without payment, the data was published.
What data was actually inside?
368,000 employee records. Social Security numbers. Dates of birth. W-2 tax forms. Payroll records. Driver's license scans. Government-issued ID scans. Corporate and personal email addresses. Home addresses. Phone numbers.
This isn't customer data—it's employee data, which in many ways is worse. W-2 forms contain everything needed for tax fraud. Government ID scans enable synthetic identity creation. The combination of SSNs, dates of birth, and home addresses is the complete package for identity theft. Current and former employees across JCPenney and sister brands including Aéropostale, Brooks Brothers, Lucky Brand, and Nautica are affected.
Who gets hurt and how?
Retail workers. Store associates. Warehouse employees. Corporate staff. Current employees and anyone who worked at JCPenney or its affiliated brands and had their information in PeopleSoft HR systems. Retail has high turnover—the employee population in these systems extends years back.
W-2 data enables tax refund fraud. File a false return before the real employee does, collect the refund, leave the victim to sort it out with the IRS. SSNs and government IDs enable new account fraud, loan applications, and synthetic identity schemes. The victims here are workers, often hourly employees, who now face potential financial harm from their employer's breach.
What did they think they were doing right?
Oracle PeopleSoft is enterprise HR software used by thousands of organizations. It's a legitimate, widely-deployed platform. Using a major vendor's solution is the expected approach for HR management at scale.
But CVE-2026-35273 was a zero-day. ShinyHunters was exploiting it before Oracle issued a patch on June 10. From May 27 to June 9, every unpatched PeopleSoft instance was vulnerable. The security of 368,000 employee records depended on patch timing for software the organization didn't develop and couldn't fix themselves.
What did they not know about their own data?
368,000 records. How many of those are active employees versus terminated employees whose data should have been purged? How many years of W-2 history was retained? How many government ID scans—uploaded once for I-9 verification—persisted in the system indefinitely?
HR systems are designed to be comprehensive. They remember everything: every hire, every termination, every tax form, every ID verification. Without aggressive retention policies, the data accumulates. The breach scope isn't determined by current headcount—it's determined by everyone who ever worked there and remained in the system.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
368,000 notifications. SSN exposure triggers notification requirements in every state. Each affected individual must be identified and contacted. Credit monitoring must be offered. The class action attorneys are already advertising—Edelson Lechtzin LLP announced an investigation the same week.
JCPenney and Catalyst Brands must also determine whether other brands in their portfolio were affected. Aéropostale, Brooks Brothers, Lucky Brand, Nautica—each brand potentially has employees in the same HR infrastructure. The notification scope expands with every subsidiary that shared the PeopleSoft instance.
What would have changed the outcome?
Knowing exactly what sensitive employee data persisted in PeopleSoft—and enforcing retention policies that minimized historical accumulation.
Zero-days happen. Software vulnerabilities get discovered and exploited before patches exist. The organizations that limit breach impact are the ones that don't keep 368,000 records when they only need 50,000. W-2 history from 2018 doesn't need to be in the production HR system in 2026. Data inventory and retention enforcement reduce what attackers can take when they get in—because eventually, they will get in.
JCPenney found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.