{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"},"incident":{"slug":"2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages","title":"Starbucks employee data stolen via cloned Partner Central login pages","date":"2026-01-19","date_precision":"day","year":2026,"victim_org":"Starbucks","sector":"Hospitality","country":"United States","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Data Breach","Credential Theft","Identity Theft"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":900,"threat_actor":null,"summary":"Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.","how_it_worked":"Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.","lessons":"Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.","confidence":"Confirmed","sources":[{"title":"Starbucks Data Breach Impacts Employees","url":"https://www.securityweek.com/starbucks-data-breach-impacts-employees/","publisher":"SecurityWeek"},{"title":"Starbucks suffers data breach via employee portal clone sites","url":"https://cyberinsider.com/starbucks-suffers-data-breach-via-employee-portal-clone-sites/","publisher":"CyberInsider"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-starbucks-employee-data-stolen-via-cloned-partner-central-login-pages"}}