Ransomware victim disclosure
← All victimsJCPenney
listed as JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group · Claimed by Shinyhunters · listed 5 days ago
Status timeline
- ListedJun 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Jun 12, 2026
About the victim
AI dossier — public-source company profileJCPenney is a major American department store retailer operating hundreds of locations nationwide, selling apparel, home goods, and accessories. The company operates under Authentic Brands Group and Catalyst Brands ownership.
- Industry
- Department Stores & Retail Apparel
- Founded
- 1902
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale including SSNs, tax records, and government identity documents affecting hundreds of thousands of individuals—meets critical threshold for identity theft and financial fraud risk.ShinyHunters claims to have exfiltrated hundreds of thousands of employee and customer records containing PII, tax documents, and government identity documents. The group issued a final extortion deadline of 15 June 2026 before threatened public disclosure.
Data the group says was taken
AI dossier — extracted from the leak post- Social Security Numbers
- Dates of Birth
- W-2 tax records
- Pay data
- Government identity documents
- Driver's licenses
- Physical document scans
What the group claims
Hundreds of thousands of records containing PII (SSN, DOB, etc.), W-2 tax records, pay data, physical scans of government identity documents, drive licenses, and a lot more was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 5 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

