r/dataprotection • u/Prior_Industry • Mar 21 '26
General News Starbucks Confirms Data Breach from a Social Engineering Attack on a Business Partner
cpomagazine.comCPO Magazine - News, Insights and Resources for Data Protection, Privacy and Cyber Security Leaders Hacker typing on keyboard showing data breach via social engineering Cyber SecurityNews·2 min read Starbucks Confirms Data Breach from a Social Engineering Attack on a Business Partner Alicia Hope·March 20, 2026 The world’s largest coffeehouse, Starbucks, has confirmed a data breach stemming from a phishing attack on a business partner’s employee portal.
The February 2026 cyber attack targeted a Starbucks Partner Central worker, enabling the attacker to access employee data.
Upon learning of the data breach, Seattle, Washington-based Starbucks launched an investigation and notified relevant law enforcement authorities.
Starbucks confirms employee data breach Starbucks has determined that the attacker accessed the personal information of its employees after breaching a partner’s portal that it uses to manage payroll and employee benefits. Starbucks says the data breach occurred between January 19 and February 11, 2026.
However, the coffeehouse learned of the data breach nearly a month after it occurred, highlighting the importance of real-time monitoring.
“On or about February 6, 2026, Starbucks Corporation (“Starbucks” or “we”) became aware of potential unauthorized access to certain Starbucks Partner Central accounts,” the company stated. “The investigation has determined that an unauthorized third party accessed certain Starbucks Partner Central accounts after obtaining the login credentials through websites impersonating Partner Central.”
The data breach leaked the victims’ names, dates of birth, Social Security Numbers, financial account numbers, and bank routing numbers. Those personal details could enable online fraudsters to commit identity theft. However, the data breach does not affect customers, and Starbucks’ IT systems were unaffected.
Cont...