CSIDB logo
Incident

Starbucks Corporation

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 13:11

Linked entities

Victim
Starbucks Corporation
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Feb 2026
Disclosed
Feb 2026
Resolved
Pending

Summary

Starbucks disclosed a data breach affecting employees after attackers obtained credentials through phishing sites that mimicked the Partner Central portal and accessed accounts containing personal and financial information. The compromised data included names, social security numbers, dates of birth, and bank account and routing numbers for nearly nine hundred workers. Law enforcement was notified and the company is providing free identity protection services to those impacted. The incident did not involve direct compromise of the company's networks, and the unauthorized access occurred over a limited time window.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 6, 2026, Starbucks Corporation detected unauthorized access to its Partner Central online portal after learning of the incident that day. The breach was traced to a phishing campaign that used counterfeit websites mimicking the Partner Central login page to harvest employee credentials. Attackers then used those stolen credentials to log into employee accounts between January 19 and February 11, 2026. Starbucks stated that its internal networks and systems were not directly compromised in the incident.

The unauthorized access exposed personal information including employees' names, Social Security numbers, dates of birth, and financial account numbers along with routing numbers. According to the breach notification filed with the Maine Attorney General’s Office, nearly 900 Starbucks employees were affected, out of a U.S. workforce exceeding 200,000. The company informed impacted individuals that some of their personal data may have been viewed by an unauthorized third party. Starbucks also noted that the breach did not involve a direct attack on its core infrastructure.

In response, Starbucks notified law enforcement about the breach and began offering free identity protection services to all affected employees. The firm submitted a formal data breach notice to the Maine Attorney General’s Office detailing the scope and timeline of the incident. Affected employees were provided with guidance on enrolling in the identity protection program as part of the company's remediation efforts.

Sources

Sources available to members: 1 source.

CSIDB