Erie Family Health Centers
Incident posture
Linked entities
- Victim
- Erie Family Health Centers
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Catalyst Brands LLC experienced a ransomware incident involving its HR and payroll servers, discovered days after it began, with ShinyHunters later claiming responsibility. An investigation confirmed that attackers accessed personal information, prompting notifications to affected individuals and several state attorneys general. Exposed data may include names, Social Security numbers, dates of birth, driver’s license numbers, passport numbers, Alien Registration numbers, U.S. military identification numbers or other government-issued IDs, contact information, financial account numbers without access information, email or username with password or security answer, and digital signatures.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Catalyst Brands LLC, a U.S. retailer and apparel company founded in January 2025 through a partnership between JCPenney and SPARC Group, disclosed a ransomware incident involving its HR and payroll servers. The incident began on May 20, 2026, and the company discovered the breach days later, on May 26, 2026. Catalyst Brands experienced the data breach on or about that May 26 date. In June 2026, the threat actor ShinyHunters claimed responsibility for the attack. The company conducted an investigation into the incident, and by August 2026 that investigation had confirmed that attackers accessed personal information.
The compromised information was associated with the company’s HR and payroll environment. The personal information identified in connection with the incident included first and last name, Social Security number, date of birth, driver’s license number, passport number, Alien Registration number, U.S. military identification number, other government-issued identification number, contact information, financial account number without access information, email or username with password or security answer, and digital signature. The incident affected individuals who received a data breach notification from Catalyst Brands LLC. The exposed information created an increased risk of identity theft and fraud for those notified individuals.
Catalyst Brands notified affected individuals and several state attorneys general on September 4, 2026. On September 11, 2026, Edelson Lechtzin LLP announced that it was investigating data privacy claims arising from the Catalyst Brands LLC data breach. The law firm stated that it was reviewing potential class action claims on behalf of individuals whose sensitive personal data may have been compromised. The announcement followed the company’s breach notification and the confirmed finding that attackers accessed personal information during the ransomware incident.
Sources
Sources available to members: 1 source.