Notices and monitoring offers
Keep the complete JCPenney or Catalyst Brands notice, envelope, email, enrollment instructions, deadline, and any later updates.
Hall Attorneys is evaluating potential claims for current and former JCPenney and associated-brand employees after a reported Oracle PeopleSoft breach involving 368,418 indexed accounts.
unique email addresses listed by HIBP
date assigned by HIBP
current and former workers in reported HR records
Answer at a glance
Have I Been Pwned says JCPenney and associated brands were targeted in a June 2026 ShinyHunters pay-or-leak campaign and that data obtained through exploitation of an Oracle PeopleSoft zero-day was later published publicly.
The exposed records reportedly came primarily from internal HR systems and concerned current and former employees. HIBP lists 368,418 unique corporate and personal email addresses.
At least one putative class action, Wu v. Catalyst Brands LLC et al., was filed by other counsel on June 17, 2026. This Hall Attorneys page concerns the firm's own investigation and does not imply that Hall Attorneys filed or appears in that case.
This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.
Mandiant observed activity aligned with CVE-2026-35273 before Oracle's advisory, making the vulnerability a zero-day during the observed campaign.
HIBP assigns June 12 as the breach date. Contemporary reporting says JCPenney and Catalyst Brands learned of the incident on or about that date.
Wu v. Catalyst Brands LLC et al., No. 4:26-cv-00668, was filed in the Eastern District of Texas by counsel not affiliated with this page.
HIBP added a verified entry listing 368,418 unique email addresses and eight compromised data categories.
Reported data categories
HIBP describes internal HR records for current and former workers. The reported combination of identity, contact, and employment data can support convincing impersonation and identity-fraud attempts.
Important distinction
HIBP's 368,418 figure counts unique email addresses. The indexed description says records include Social Security numbers, but the HIBP category label groups those values under government-issued IDs.
Who may want to contact us
The reported records are primarily employee HR data. The investigation focuses on workers and former workers whose personal information may have been retained in affected PeopleSoft systems.
Current or former JCPenney employees whose corporate or personal email appears in the HIBP entry
Current or former workers for associated Catalyst Brands whose HR records may have been involved
People who received an incident notice or identity-monitoring offer
Workers experiencing payroll-themed phishing, tax fraud, identity theft, account misuse, financial loss, monitoring costs, or lost time
What to preserve
Preserve relevant records, but do not send passwords, complete bank-account numbers, Social Security numbers, tax forms, government identification, or unredacted credit reports through ordinary website forms.
Keep the complete JCPenney or Catalyst Brands notice, envelope, email, enrollment instructions, deadline, and any later updates.
Preserve records showing your current or former employment with JCPenney or an associated brand, including dated account, enrollment, employment, alumni, transaction, or correspondence records.
Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.
Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.
Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.
Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.
Investigation focus
Hall Attorneys is reviewing the reported PeopleSoft exploitation, the HR data involved, notice and monitoring offered to workers, retention of former-worker information, and concrete harms.
Public records reviewed
The sources below distinguish HIBP's verified dataset description, the technical PeopleSoft campaign record, and a separate lawsuit filed by other counsel.
Have I Been Pwned ·
Lists 368,418 unique email addresses, eight compromised data categories, the reported PeopleSoft access path, and the public release.
Read source: JCPenney Data BreachOracle ·
Oracle says the PeopleSoft PeopleTools vulnerability is remotely exploitable without authentication, may allow remote code execution, and affects supported versions 8.61 and 8.62.
Read source: Security Alert Advisory — CVE-2026-35273Google Threat Intelligence Group and Mandiant ·
Describes activity attributed to UNC6240, also known as ShinyHunters, observed from May 27 through June 9 and aligned with exploitation of CVE-2026-35273.
Read source: ShinyHunters Targets Education Sector with Oracle PeopleSoft ExploitJustia Dockets ·
Public docket summary for a putative class action filed by other counsel in the Eastern District of Texas.
Read source: Wu v. Catalyst Brands LLC, et al.Contact the firm
Contact Hall Attorneys with your general employment dates and brand, whether you received notice, and a summary of suspicious activity or loss. Do not include passwords, Social Security numbers, bank details, tax forms, or identification documents in an initial message.
Frequently asked questions
No. Public dockets show that Wu v. Catalyst Brands LLC et al. was filed by other counsel. Hall Attorneys is separately investigating potential claims.
Have I Been Pwned lists 368,418 unique email addresses. That figure does not necessarily equal the number of distinct people.
HIBP says the records primarily related to internal HR systems and impacted current and former employees of JCPenney and associated brands.
Reported data includes names, dates of birth, Social Security numbers, corporate and personal emails, phone numbers, home addresses, job titles, usernames, and other government-issued IDs.
HIBP reports that the data was obtained through exploitation of a critical Oracle PeopleSoft zero-day vulnerability. Oracle and Mandiant separately documented CVE-2026-35273 and the broader campaign.
Attorney Advertising
Hall Attorneys is not affiliated with JCPenney or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.