Starbucks Data Breach – Hundreds of Users’ Personal Data Exposed
Starbucks Corporation has reported a data breach impacting employee accounts. Unauthorized access was achieved via a phishing scheme targeting the company's internal Partner Central accounts.
Starbucks Corporation has reported a data breach impacting employee accounts. Unauthorized access was achieved via a phishing scheme targeting the company's internal Partner Central accounts.
On or about February 6, 2026, Starbucks discovered the unauthorized access to Partner Central, the portal used for employee management. The breach involved threat actors using phishing tactics to obtain login credentials and access sensitive data.
The breach exposed several categories of personal and financial information, including:
Full names Social Security Numbers (SSNs) Dates of birth Financial account numbers and routing numbers
The exposure of these details increases risks of identity theft and fraud. Affected individuals have been notified through a breach notice dated March 10, 2026.
Starbucks Corporation has reported a data breach impacting employee accounts.
Starbucks initiated an internal investigation with cybersecurity experts and notified law enforcement. Security measures have been enhanced to safeguard Partner Central accounts.
As a remediation effort, Starbucks offers affected employees a complimentary 24-month membership to Experian IdentityWorks, which includes:
Dark web surveillance Credit monitoring Identity restoration services Identity theft insurance coverage up to $1 million
Enrollment must occur by June 30, 2026, to activate these services.
Recommendations for Affected Employees
Regularly monitor financial accounts and credit reports Place a fraud alert or security freeze with credit bureaus Change passwords on accounts sharing credentials with Partner Central Exercise caution with unsolicited emails requesting personal information
This incident underscores the need for robust security measures against credential phishing, particularly for systems housing sensitive data. Implementing phishing-resistant multi-factor authentication (MFA) is critical for organizational security.
Based on reporting by Cyber Security News.
