Starbucks recently disclosed a data breach that affected hundreds of its employees after unauthorized access to accounts in its internal personnel management system. According to the company, cybercriminals were able to gain access to accounts on the Starbucks Partner Central platform , which is used by employees to manage employment, benefits and personal information .

The incident highlights once again the challenges facing large multinational companies in protecting sensitive employee data, in an era where cyberattacks are becoming increasingly targeted and sophisticated.
The world's largest coffee chain in the spotlight
Starbucks is considered the world's largest coffee chain, with more than 380,000 employees. The company operates nearly 41,000 stores in 88 countries, making it a huge organization with extensive digital infrastructure and human resources management systems.
See also: Hive0163 uses AI malware Slopoly in ransomware attacks
In such organizations, even a small security breach can lead to a large-scale data leak, as internal information systems manage huge volumes of personal and financial information.
How the breach happened
According to notification letters filed with the Maine Attorney General and sent to affected employees, the company discovered the incident on February 6, 2026.
After discovering the breach, Starbucks launched an investigation in collaboration with external cybersecurity experts. The results showed that the attackers had gained access to 889 Partner Central accounts.
The accounts were apparently accessed through phishing websites that mimicked the real Partner Central login interface. Employees were tricked into entering their credentials on the fake pages, allowing the attackers to obtain their login details.
Chronology of the attack
According to the research data, cybercriminals had access to employee accounts from January 19 to February 11, 2026.This means that for several weeks the attackers had the ability to browse the system and obtain sensitive data.
See also: Telus Digital breach – Hackers say they stole 1PB of data
It remains unclear why it took about five days from the discovery of the breach to the complete removal of the attackers from the company's systems. In similar cases, cybersecurity experts often need time to map the extent of the breach before fully isolating the threat.

What data was exposed?
The data that may have been leaked is particularly sensitive. These include:
- Employee names
- Social Security Numbers
- Dates of birth
- Bank account numbers and routing numbers
Disclosing such information significantly increases the risk of identity theft, financial fraud, and unauthorized banking transactions.
The measures taken by Starbucks
After confirming the breach, the company said it immediately took a series of actions to mitigate the impact. Among other things, it notified the relevant law enforcement authorities, while also strengthening security mechanisms related to access to Partner Central accounts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, Starbucks warned employees to carefully monitor their bank accounts for possible suspicious transactions that could indicate fraud.
See also: APT28 spies on the Ukrainian military with BEARDSHELL and COVENANT
As an additional protection measure, the company is offering affected employees protection identity theft and credit history monitoring services through Experian IdentityWorks (for two years).
Previous security incidents
This is not the first time Starbucks has been linked to cybersecurity incidents. In 2022, the company's Singapore branch confirmed a data breach affecting more than 219,000 customerswhen an attacker breached a third-party vendor's systems that stored customer data.
At the same time, the company was also affected by a major ransomware in 2024, when the Termite targeted provider Blue Yonderthat works with Starbucks.

The growing threat to large organizations
The incident highlights the ever-growing threat facing large businesses from phishing attacks and credential theft. As companies increasingly rely on digital tools to manage their workforce and operations, employee accounts are often the easiest entry point for cybercriminals.
For this reason, experts emphasize the importance of multi-factor authentication (MFA), continuous employee training on phishing attacks, and the adoption of advanced threat detection mechanismsso that similar incidents can be identified and dealt with much more quickly in the future.
Source: www.bleepingcomputer.com
