TechNewsReel
Live

ShinyHunters Breach JCPenney and Catalyst Brands via Oracle PeopleSoft Flaw

The theft of W-2s and government ID scans exposes employees and customers to severe identity theft risks.

TechNewsReel Newsroom · September 12, 2026

A massive data breach has compromised the sensitive personal and professional information of individuals associated with JCPenney and Catalyst Brands LLC. The attack, claimed by the hacking group ShinyHunters in June 2026, represents a critical failure in the security of high-value identity data.

According to reports and legal filings, the breach involved the theft of highly sensitive personally identifiable information (PII). The stolen data includes Social Security Numbers (SSNs), dates of birth, payroll data, and W-2 tax records. Most alarmingly, the attackers obtained physical scans of government identity documents, providing them with the raw materials necessary for sophisticated identity fraud. ShinyHunters has claimed to have stolen hundreds of thousands of records during the operation.

A Wider Campaign of Exploitation

This incident was not an isolated attack but part of a broader, systemic campaign orchestrated by ShinyHunters. The group exploited a zero-day vulnerability in Oracle PeopleSoft applications, identified as CVE-2026-35273. This specific flaw allowed the attackers to penetrate the defenses of over 100 organizations globally. Other high-profile victims of this same campaign include Kodak and the Council of Europe, signaling a coordinated effort to target entities relying on the same enterprise software infrastructure.

High-Stakes Identity Risks

The severity of this breach stems from the nature of the exfiltrated data. While many breaches involve emails or passwords that can be reset, the loss of W-2s and government ID scans is permanent. These documents are often used as primary verification for loans, credit accounts, and government benefits. By possessing these scans, attackers can bypass traditional identity verification hurdles, leaving affected employees and customers vulnerable to long-term financial fraud and identity theft that can take years to resolve.

Legal and Regulatory Fallout

In the wake of the exposure, the law firm Edelson Lechtzin LLP has launched a formal investigation into the breach. The firm is currently working to identify the full scope of the compromised data to pursue a potential class action lawsuit on behalf of the affected individuals. As the investigation continues, the focus remains on whether JCPenney and Catalyst Brands maintained adequate security patches for their Oracle systems and how the vulnerability was allowed to persist long enough for ShinyHunters to extract such a vast volume of sensitive documentation.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.