Starbucks Data Breach Exposes Personal Data of Hundreds of Users
Starbucks Corporation has reported a cybersecurity incident affecting 889 individuals, compromising personal and financial data. The breach involved the Starbucks Partner Central platform, which manages human resources, employee benefits, and payroll…
Starbucks Corporation has reported a cybersecurity incident affecting 889 individuals, compromising personal and financial data. The breach involved the Starbucks Partner Central platform, which manages human resources, employee benefits, and payroll details.
The unauthorized access occurred from January 19 to February 11, 2026. After detecting the activity on February 6, Starbucks revoked the attackers' access by February 11. The investigation revealed that threat actors used credential harvesting techniques, directing employees to phishing websites mimicking the Starbucks Partner Central portal.
The attack exposed sensitive information including employees' full names, dates of birth, Social Security numbers, financial account numbers, and banking routing numbers associated with direct deposits. In response, Starbucks terminated unauthorized access, notified federal law enforcement, and enhanced its internal security controls.
Starbucks Corporation has reported a cybersecurity incident affecting 889 individuals, compromising personal and financial data.
Starbucks is offering 24 months of identity theft protection and credit monitoring services to affected individuals through Experian Credit Plus 1B.
In November 2024, Starbucks experienced operational disruptions due to a ransomware attack on Blue Yonder, a third-party supply chain software provider. Additionally, a breach in September 2022 exposed personal details of over 219,000 customers from the company's Singapore division.
Based on reporting by GBHackers.
