// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
ColdRecon / Breach Radar / JCPenney
Breach Record

JCPenney

DISCLOSED 2026-06-12 · STOLEN CREDS · 368,418 RECORDS EXPOSED

In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from JCPenney through the exploitation of a critical zero-day vulnerability in Oracle PeopleSoft was later published publicly. The exposed records indicated they primarily related to internal HR systems and impacted current and...

The record

What we know

Disclosed
2026-06-12
Attack vector
Stolen Creds
Records exposed
368,418
Domain
jcpenny.com
Data classes exposed
Dates of birthEmail addressesGovernment issued IDsJob titlesNamesPhone numbersPhysical addressesUsernames
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the JCPenney disclosure. It updates if new public reporting emerges. All tracked breaches →

JCPenney just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →