JCPenney
Disclosed Jun 20, 20263 months ago368,418 accountsUnverified
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign . Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and former employees. The data included 368k corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers and home addresses.
What is known
| People affected | 368,418 (accounts in the leaked data, per Have I Been Pwned) |
|---|---|
| Disclosed | Jun 20, 2026 |
| Happened | Jun 12, 2026 |
| Attack | Insider |
| Data exposed | Dates of birth, Emails, Government IDs, Employment, Names, Phone numbers, Addresses |
| Sector | Tech |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Check your email | Have I Been Pwned |
Sources
| Source | |
|---|---|
| Have I Been Pwned: JCPenneyhaveibeenpwned.com · Aggregator | Aggregator |
Notices filed
| Where | Filed | People |
|---|---|---|
| Have I Been Pwnedaccounts in the data | Jun 20 | 368,418 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Have I Been Pwned). Record counts are as reported. Not legal advice.