J.C. Penney Corporation, Inc.
bd_aa97c4c519fc03cb · schema v1 · pii pii-v1
Full breach record for J.C. Penney Corporation, Inc. →J.C. Penney notified the NH AG of a third-party vendor security incident involving its Microsoft 365 environment between April and August 2017. The incident potentially exposed supplier PII including names, addresses, SSNs, and EINs. Approximately 7 NH residents were affected. J.C. Penney engaged forensic investigators and provided 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2017
Begins
Mar 27, 2018
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- Massachusetts State AGbd_421530ebdabfde732018-03-27Verified
Filing propagation · 2 filings · 2 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.