Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
← Back to the register

JCPenney

CriticalConfirmedEducation

In June 2026, JCPenney suffered a data breach. 368,418 accounts were affected. The exposed data includes dates of birth, email addresses, identity documents, employment data, names, phone numbers, postal addresses and account identifiers.

Disclosed on
June 20, 2026
Incident dated
June 12, 2026
Accounts affected
368,418
Sector
Education
Country
International or undetermined
Cause
Undisclosed

Exposed data

  • Date of birth
  • Email address
  • Identity document
  • Employment data
  • Full name
  • Phone number
  • Postal address
  • Customer ID

You are only affected if you had an account or an order with this organisation.

What you can do

  • Expect phishing attempts quoting your name and this company. A message that knows your details is not legitimate for that reason.
  • These documents enable identity theft, and cannot be reissued at will. Keep the notification letter: it proves where the leak came from if an account is opened in your name.
  • You can ask the organisation exactly what was exposed about you (right of access), and complain to the DPA if no answer comes within a month.

Sources

Entry built from Have I Been Pwned’s structured data, with no model rewriting. Spotted an error, or have a correction? Write to us and the entry will be fixed. Contact