Last updated 2 weeks ago
In June 2026, retailer JCPenney and associated brands were targeted in a ShinyHunters 'pay or leak' extortion campaign. The breach exposed 368,418 records primarily from internal HR systems, impacting current and former employees. The data was published publicly after the extortion demands were not met.
The attack chain involved exploitation of a critical zero-day vulnerability in Oracle PeopleSoft, which provided initial access to JCPenney's internal systems. The threat actor, ShinyHunters, exfiltrated data including corporate and personal email addresses, names, dates of birth, Social Security numbers, phone numbers, and home addresses. The breach specifically targeted HR systems, indicating a focus on employee personal identifiable information (PII).
No post-incident details such as regulatory actions, litigation, ransom payment, or containment milestones were provided in the article.
Exploitation of a critical zero-day vulnerability in Oracle PeopleSoft
JCPenney's reliance on Oracle PeopleSoft without timely patching of a critical zero-day vulnerability allowed ShinyHunters to gain initial access and exfiltrate sensitive HR data. The exposure of Social Security numbers and home addresses for 368,418 employees underscores the need for robust vulnerability management and segmentation of HR systems from external-facing applications. This breach highlights the importance of proactive threat intelligence and rapid patch deployment to defend against extortion-focused threat actors.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor