Were you recently affected by a data breach?

Catalyst Brands Data Breach

Catalyst Brands, the retail parent company of JCPenney and other national apparel brands, disclosed that a third-party vendor supporting its HR and payroll services suffered a cybersecurity incident exposing employee personal information.

Catalyst Brands
Date of Breach: On or around May 26, 2026 (confirmed August 5, 2026)
CAU logo

Who was affected:

Clients of Catalyst Brands

Impacted Data:

Names, Social Security numbers, dates of birth, driver’s license numbers, passport numbers, Alien Registration numbers, U.S. military or other government-issued identification numbers, contact information, financial account numbers, email or usernames with passwords or security answers, and digital signatures

Catalyst Brands LLC, the retail company formed in 2025 through the merger of JCPenney and Sparc Group and whose brands include JCPenney, Aeropostale, Brooks Brothers, Eddie Bauer, Lucky Brand, and Nautica, has disclosed a cybersecurity incident affecting personal information tied to a third-party vendor that supports its HR and payroll-related services. Companies that rely on outside vendors to manage sensitive employee and customer data still bear a responsibility to ensure that data is properly protected, wherever it is ultimately stored.

Catalyst Brands’ Data Breach Investigation

According to a notification letter filed with the California Attorney General, Catalyst Brands became aware of a cybersecurity incident on or around May 26, 2026, involving unauthorized access to certain servers managed by a third party that supports the company’s HR and payroll-related services. Following an investigation with the assistance of external cybersecurity experts, Catalyst Brands determined on August 5, 2026 that an unauthorized third party had obtained personal information belonging to certain individuals in connection with the incident.

Vendor-side breaches like this one are an increasingly common way for sensitive workforce data to be exposed, since a single compromised HR or payroll processor can hold records for the employees of many different client companies at once, making it an efficient target for cybercriminals compared to attacking each employer directly. Once inside such a system, an unauthorized actor can potentially access years of accumulated personnel records, including Social Security numbers, government identification, and financial account details submitted for payroll processing.

Separately, Catalyst Brands and JCPenney were also reported in press coverage to have experienced an earlier cybersecurity incident around June 12, 2026, in which a cybercrime group calling itself ShinyHunters claimed to have stolen records from JCPenney and several affiliated brands. That reported incident, which is not the same disclosure covered by this vendor-breach notification letter, involved a different detection date and separate circumstances; individuals should not assume the two incidents are one and the same, though either could result in a personal notification letter depending on the specific data involved.

Catalyst Brands took steps to block the unauthorized access once discovered, notified law enforcement, and implemented additional security measures to help prevent a similar incident in the future. The company is offering identity protection and credit monitoring services through Experian IdentityWorks for 24 months at no cost to affected individuals.

When Did This Breach Occur?

Catalyst Brands states that the unauthorized access to the third-party vendor’s servers began on or around May 26, 2026, and that the company confirmed personal information had been obtained by an unauthorized party on August 5, 2026.

What Information Was Breached?

Catalyst Brands’ notification letter states that the types of information involved varied by affected individual and could include full name, Social Security number, date of birth, driver’s license number, passport number, Alien Registration number, U.S. military identification number or other government-issued identification number, contact information, financial account numbers, email addresses or usernames together with passwords or security answers, and digital signatures.

What You Can Do

Catalyst Brands is offering affected individuals two years of complimentary identity protection and credit monitoring through Experian IdentityWorks. If you received a letter, it includes a unique activation code and enrollment deadline. It’s also worth ordering a free copy of your credit report from each of the three major credit bureaus, watching your account statements for unfamiliar activity, and considering a fraud alert or credit freeze on your credit file.

File a Data Breach Lawsuit Against Catalyst Brands

If you received a notice from Catalyst Brands about this incident, keep it as documentation, since it can help establish that your information was involved if you decide to pursue legal action.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 10, 2026
Date of Breach: Not publicly disclosed in the firm's notice
Date of Breach: Unauthorized access discovered on or about August 17, 2026, following an extensive forensic investigation
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.