Catalyst Brands LLC
Incident posture
Linked entities
- Victim
- Catalyst Brands LLC
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Catalyst Brands LLC experienced a ransomware attack on its HR and payroll servers that was first detected a few days after it began. The ransomware group ShinyHunters claimed responsibility, and an subsequent investigation confirmed that attackers accessed a range of personal data, including names, Social Security numbers, dates of birth, driver’s license and passport numbers, government identifiers, contact details, financial account numbers, email credentials and digital signatures. The company notified affected individuals and several state attorneys general after the confirmation. Individuals who received the breach notice face an elevated risk of identity theft and fraud. Edelson Lechtzin LLP has launched an investigation into potential claims arising from the exposure.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Catalyst Brands LLC, a U.S. retailer and apparel company founded in January 2025 through a partnership between JCPenney and SPARC Group, experienced a ransomware incident that began on May 20, 2026, targeting its HR and payroll servers. The company discovered the breach on May 26, 2026, and the ransomware group ShinyHunters publicly claimed responsibility in June 2026. An internal investigation concluded in August 2026 that unauthorized actors had accessed personal information stored on the affected systems. On September 4, 2026, Catalyst Brands LLC notified affected individuals and several state attorneys general about the breach.
The exposed data may have included first and last name, Social Security number, date of birth, driver’s license number, passport number, Alien Registration number, U.S. military identification number or other government‑issued identification number, contact information, financial account numbers without access credentials, email or usernames paired with passwords or security answers, and digital signatures. Individuals who received the breach notification were identified as potentially facing an increased risk of identity theft and fraud. In response to the incident, the national class action law firm Edelson Lechtzin LLP announced on September 11, 2026, that it is investigating data privacy claims arising from the breach and will evaluate potential legal remedies on behalf of affected individuals at no cost.
The firm’s investigation will consider whether a class action can be pursued to address the alleged mishandling of personal information, and it will assess the rights and possible claims of those whose data may have been compromised. Catalyst Brands LLC’s disclosure indicated that the breach was discovered days after the initial ransomware activity and that the notification to regulators and individuals occurred in early September. No further details about the attacker’s methods, containment measures, or specific remediation steps were provided in the source material.
Sources
Sources available to members: 1 source.