JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group
Attack Intelligence
JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group was compromised in a ransomware attack attributed to shinyhunters in June 2026. The organization, operating in the Consumer Services sector in United States, was added to the group's data leak site as part of an extortion campaign.
shinyhunters operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Hundreds of thousands of records containing PII (SSN, DOB, etc.), W-2 tax records, pay data, physical scans of government identity documents, drive licenses, and a lot more was compromised. This is a final warning to reach out by 15 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 12 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-35273, which may have been leveraged as initial access vectors or for lateral movement.