Data breach
Catalys Brands
- Records
- 149,768
- Breach date
- 12 June 2026Estimated
- Added
- 8 July 2026
What was exposed
7 types of data · 6 more reported · 2 put you at serious risk
- Email addresses149,768
- Names145,894
- Street addresses53,934
- Phone numbers38,318
- Dates of birth12,053
- Social security numbers7,901
- Passport numbers158
- Driving licence numbersReported, not counted
- Government IDsReported, not counted
- Bank account numbersReported, not counted
- PasswordsReported, not counted
- UsernamesReported, not counted
- Security questionsReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
Catalyst Brands, the retail holding company behind JCPenney, Brooks Brothers, Aéropostale, Eddie Bauer, Lucky Brand and Nautica, has confirmed that a cyberattack exposed personal information belonging to hundreds of thousands of people. According to our investigation team, a listing tied to this breach contains 149,768 rows of records, including 145,894 names, 149,768 email addresses, 53,934 street addresses, 38,318 phone numbers, 12,053 birthdays, 7,901 Social Security numbers and 158 passport numbers. The listing credits the hacking group ShinyHunters and carries an estimated attack date of June 12, 2026. An official notice filed with multiple state attorneys general and summarized by ClaimDepot puts the total number of affected individuals at 187,341, a higher figure than the row count in our listing. The difference may reflect overlap with related listings or different counting methods, and it is not fully explained as of September 25, 2026.
Breach Timeline
May 20, 2026: A ransomware attack struck servers used for Catalyst Brands' HR and payroll-related services, according to the company's notice filed with state attorneys general. The company became aware of the unauthorized access on or around May 26, 2026.
June 12, 2026: ShinyHunters posted a claim on the Tor network stating it had breached data from Catalyst Brands and related brands, threatening release unless the companies responded. The post gave the organizations until June 15 to make contact, according to reporting tracked by SpotlightMonitor.
June 18, 2026: The law firm Edelson Lechtzin LLP announced it was investigating potential privacy claims over the breach, reporting that the companies had confirmed data including Social Security numbers, dates of birth, W-2 tax forms, payroll records and government-issued ID scans, per PR Newswire.
August 5, 2026: Catalyst Brands' investigation confirmed that an unauthorized party had obtained personal information from the affected systems.
September 4, 2026: The company mailed notification letters to affected individuals and filed breach notices with state attorneys general.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, dates of birth, email addresses, phone numbers, names, street addresses and passport numbers.
The company's notice filed with state attorneys general describes a broader set of records that varied by individual, including first and last name, Social Security number, date of birth, driver's license number, passport number, Alien Registration number, U.S. military identification number or other government-issued identification number, contact information, financial account number without access information, email or username with password or security answer, and digital signature.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers combined with names, dates of birth and addresses are the ingredients for identity theft. Criminals can use them to open new credit accounts, file fraudulent tax returns claiming someone else's refund, or impersonate victims with government agencies and medical providers. Exposed passwords and security answers enable account takeovers, especially where people reuse passwords across sites. Scammers may also pose as Catalyst Brands or Experian in phishing calls and emails that reference this breach to extract more information. Because the exposed records include employment and payroll data, victims should watch for fraud tied to employment records as well as financial accounts.
What Is Catalys Brands Doing in Response?
According to the notice summarized by ClaimDepot, Catalyst Brands is offering affected individuals 24 months of free identity protection and credit monitoring through Experian IdentityWorks, with enrollment using an activation code from the notification letter and a deadline of December 31, 2026. The company has set up a toll-free line at 833-918-1023, available 8 a.m. to 8 p.m. Central Time, and Experian's fraud line at 1-833-918-7467. A class action investigation announced in June 2026 is ongoing.
What Should You Do If You Were Affected?
Enroll in the free Experian IdentityWorks credit monitoring using the activation code in your letter before December 31, 2026.
Place a free credit freeze and fraud alert with the three major credit bureaus.
File your tax return early to block a fraudulent filing, and consider an IRS Identity Protection PIN.
Change passwords on any account tied to your work email and stop reusing passwords across sites.
Watch for phishing emails and calls that mention the breach.
Review bank, credit card and health insurance statements for unfamiliar activity.
If you received a notification letter, keep it; it may be needed for documentation.
In the news
- ClaimDepot summary of Catalyst Brands' breach notice and state attorney general filingsclaimdepot.com (opens in a new tab)
- California Attorney General breach reportoag.ca.gov (opens in a new tab)
- PR Newswire: Edelson Lechtzin LLP investigation announcementprnewswire.com (opens in a new tab)
- SpotlightMonitor breach trackernews.spotlightmonitor.com (opens in a new tab)
