What happened
Attackers stood up counterfeit websites mimicking Starbucks' Partner Central employee portal and used the harvested credentials to log into real accounts between 19 January and 11 February 2026. Starbucks detected the activity on 6 February. Nearly 900 of the company's more than 200,000 US workers were affected, with names, Social Security numbers, dates of birth and bank account and routing numbers exposed. No threat actor was named.
How the deception worked
Rather than attacking Starbucks' infrastructure, the crew rebuilt its HR portal. Employees who reached the clone, most plausibly through phishing messages or search results, entered their Partner Central username and password into a page that looked exactly like the one they use for pay and benefits. The attackers replayed those credentials against the live portal and pulled the payroll and tax records held there, information directly usable for identity theft and payroll-diversion fraud. Detection came three weeks into the access window.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant MFA on the HR portal and domain monitoring for lookalike registrations would have blocked credential replay and shortened the three-week detection gap.
Sources (2)
- Starbucks Data Breach Impacts EmployeesSecurityWeek·securityweek.comOpen ↗
- Starbucks suffers data breach via employee portal clone sitesCyberInsider·cyberinsider.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.