[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9tdvie2mjhyx":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":12,"affectedCountUnit":20,"hasEnglishDescription":4,"contentLocale":21,"availableLocales":22,"translations":24,"severity":27,"dataClasses":28,"description":37,"seoTitle":38,"seoDescription":39,"logoUrl":40,"isVerified":4,"isSensitive":41,"isSpamList":41,"isMalware":41,"company":42},"6a452308a20f867c8ba8e77f","jcpenney","JCPenney 2026 Data Breach","jcpenney.com","2026-06-12T00:00:00.000Z","2026-06-20T03:02:45.000Z",null,"2026-07-29T18:23:21.781Z","Verified breach record","https:\u002F\u002Fbreachnews.com\u002Fbreaches\u002Fshinyhunters-publishes-alleged-data-from-american-tower-jcpenney-ralph-lauren-and-other-victims\u002F",[15,17],"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fshinyhunters-targets-education-sector-oracle-exploit",368418,"known","email_identifiers","en",[21,23],"tr",{"en":25,"tr":26},{"slug":7},{"slug":7},"High",[29,30,31,32,33,34,35,36],"Dates of birth","Email addresses","Government-issued identification numbers","Job titles","Names","Phone numbers","Physical addresses","Usernames","\u003Cp>\u003Cstrong>The JCPenney 2026 data-breach record\u003C\u002Fstrong> concerns a published dataset attributed to employee-focused data from JCPenney and associated brands. A verified external breach record dates the event to June 12, 2026 and reports 368,418 unique email addresses. This is an email measure from the external corpus; production has no JCPenney import job or locally indexed person-level corpus.\u003C\u002Fp>\n\n\u003Ch2>What information about the event was confirmed?\u003C\u002Fh2>\n\u003Cp>Independent reporting dated June 15 documented a threat actor listing JCPenney and some associated brands under Catalyst Brands and Authentic Brands Group on an extortion site. Follow-up reporting dated June 17 said the actor had published data attributed to JCPenney. The reports relay claims involving employee, identity, payroll, and tax data while explicitly stating that they had not independently authenticated the full dataset and that company confirmation was unavailable.\u003C\u002Fp>\n\u003Cp>The external corpus subsequently added to a verified breach record supports the exact email count and structured data types. That verification does not mean the company confirmed the attack narrative, threat actor, or initial access method. June 12 should be read as the record and threat-listing date; the exact date of network access is unknown.\u003C\u002Fp>\n\n\u003Ch2>Which data types are in scope?\u003C\u002Fh2>\n\u003Cp>The structured list contains eight classes: dates of birth, email addresses, government-issued identification numbers, job titles, names, phone numbers, physical addresses, and usernames. The external record's narrative additionally mentions Social Security numbers, while independent reporting relays claims involving identity-document scans and payroll or tax documents. It should not be assumed that every field was present for every email record.\u003C\u002Fp>\n\u003Cp>Passwords, payment cards, bank accounts, customer orders, purchase history, and loyalty-program data are not confirmed structured classes. Although the record appears employee-focused, the 368,418 value is not an employee or person count and should not be expanded to JCPenney's entire customer base.\u003C\u002Fp>\n\n\u003Ch2>What is the boundary of the PeopleSoft link?\u003C\u002Fh2>\n\u003Cp>Google threat intelligence confirms a broader extortion campaign targeting Oracle PeopleSoft infrastructure between May 27 and June 9, with CVE-2026-35273 exploited as a zero-day. That report does not name JCPenney. The claim that JCPenney data was obtained through the PeopleSoft vulnerability is therefore retained as possible campaign context, not presented as a verified initial access method.\u003C\u002Fp>\n\n\u003Ch2>How should the count and risk be interpreted?\u003C\u002Fh2>\n\u003Cp>The 368,418 value is the number of unique email addresses in the verified external corpus; it is not a source-row, employee-account, or unique-person measure. With no local import, it is not displayed as a local total. A match also does not prove that all eight fields were present for the same person.\u003C\u002Fp>\n\u003Cp>People who received a notice can monitor credit reports, tax accounts, payroll activity, and former-employee portals according to the fields named in their own letters. Unexpected human-resources, W-2, benefits, or identity-verification messages should be confirmed through a separate official channel; identity documents and one-time codes should not be supplied through a suspicious link.\u003C\u002Fp>","JCPenney 2026 Data Breach (368.4 Thousand Email Identifiers)","The 2026 JCPenney record contains 368,418 verified unique emails. Review eight employee-focused data types and the company-confirmation boundary.","\u002Fuploads\u002Flogo\u002Fjcpenney_com.webp",false,{"name":43,"sector":44,"country":45,"website":9,"websiteArchiveUrl":46,"websiteStatus":47,"websiteCheckedAt":48},"JCPenney","Retail","United States","","active","2026-07-29T18:14:28.000Z"]