Starbucks reported that 889 people were affected after attackers used websites impersonating its Partner Central employee portal to obtain login credentials. Reported exposed data included names, Social Security numbers, dates of birth, and financial account and routing numbers. Starbucks said customer data was not affected and offered eligible individuals 24 months of Experian identity-theft protection and credit monitoring.
The 889-person figure comes from Starbucks’ Maine breach filing and does not establish that all affected people were current U.S. employees. The public materials do not provide a complete breakdown of current employees, former employees, licensee workers, contractors, or other account holders.
What Starbucks disclosed
The Maine Attorney General filing lists the incident period as January 19 through February 11, 2026. Starbucks said it discovered potential unauthorized access on February 6. The filing lists March 10, 2026 as the consumer-notification date; BleepingComputer published its report on March 13.
The filing records 889 affected people, including five Maine residents. It is a state filing and does not, by itself, prove that 889 is a worldwide total. The filing is available at Maine’s breach-notification database.
#1 Best Overall
How the attackers got into Partner Central
According to Starbucks’ statement reported by BleepingComputer, a limited number of retail partners interacted with deceptive websites designed to look like Partner Central. The attackers captured credentials from those sites and then used them to access certain employee accounts.
Partner Central is an employee-facing portal for employment details, personal information, benefits and human-resources information. The available reporting does not name a threat actor or ransomware group. It also does not establish that Starbucks’ point-of-sale, rewards, mobile-app or customer systems were accessed.
What information was reportedly exposed?
BleepingComputer, citing Starbucks’ breach notification, reported these categories:
- Names
- Social Security numbers
- Dates of birth
- Financial account numbers
- Financial routing numbers
The public Maine summary does not enumerate every field, and the sources do not show that every compromised account contained every listed category. Check the individual notice for the exact information associated with your account.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWere Starbucks customers affected?
A Starbucks spokesperson told BleepingComputer that customer data was not affected in this incident. That statement concerns this 2026 employee-account compromise; it should not be combined with reports about separate historical incidents involving customers or vendors.
What affected employees should do now
1. Enroll using the notice you received
The Maine filing says Starbucks offered 24 months of Experian identity-theft protection and credit monitoring. The filing calls the product “Experian Credit Plus 1B,” while BleepingComputer referred to Experian IdentityWorks. Product names can differ between the public filing and secondary coverage, so use the enrollment instructions and deadline in your personal Starbucks notice rather than a link in an unsolicited message.
2. Consider a credit freeze
Monitoring alerts you to certain changes; it does not block a criminal from applying for new credit. A freeze restricts prospective creditors from accessing your file and can be lifted temporarily when you need legitimate credit. Use the bureaus’ official pages:
A fraud alert is a different, less restrictive option that asks creditors to take extra steps to verify your identity.
3. Check bank and payroll activity
Because financial account and routing numbers were reportedly among the exposed data, review bank statements, ACH transactions and direct-deposit details. Ask your bank whether an account should be replaced or closed if your notice confirms that its number was involved. Do not close every account automatically; follow the bank’s guidance and the facts in your notice. Confirm any payroll-change request through a known Starbucks channel, not through a message that contacted you unexpectedly.
4. Change reused passwords and enable multifactor authentication
Change any password reused for Partner Central or another service. Use a unique password for each account and turn on multifactor authentication wherever it is available. Never provide a one-time code to someone who calls or messages claiming to be HR, Starbucks, a bank or Experian.
5. Expect follow-on phishing
The original incident reportedly involved fake employee websites, so criminals may try to exploit the news with fake enrollment pages, payroll forms, password resets or verification calls. Navigate directly to official websites and independently verify contact details through Starbucks’ internal resources, official employee communications or the formal notice.
6. Report suspicious activity quickly
Contact your bank or payroll department immediately about unfamiliar transactions or account changes. Also contact the credit bureaus and the appropriate government identity-theft reporting service if fraudulent accounts or transactions appear.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesIf you were not contacted
The public filing confirms 889 affected people, but it does not identify every person who may have interacted with Partner Central or provide a complete account-by-account list. Check Starbucks communications and personal mail, then contact Starbucks’ privacy or breach-response team using independently verified information. Ask whether you are eligible for the offered protection service. Continue watching credit, bank and payroll activity even if you have not received a notice.
What remains unknown
- The identity of the attacker or any affiliated group
- Whether stolen information was sold or publicly released
- How many accounts contained each specific data category
- Whether every affected person’s Social Security number or financial data was accessed
- Whether Starbucks paid a ransom
- Whether anyone suffered confirmed identity theft or fraudulent transactions
The dates show that the reported access period extended to February 11 even though Starbucks discovered potential unauthorized access on February 6. The available sources do not establish why those dates differ, so they should not be treated as a finding of negligence or a confirmed five-day failure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.This is not the 2024 Blue Yonder incident
Starbucks has also been associated with a separate cyberattack on Blue Yonder, a third-party software provider, in November 2024. A later Starbucks Coffee Japan notice said information relating to approximately 31,500 employees and former employees had been exposed through Blue Yonder’s data-transfer system. That event is separate from the 2026 Partner Central credential compromise.
| Issue | 2026 Partner Central incident | Blue Yonder/Starbucks Japan incident |
|---|---|---|
| Primary geography | U.S. reporting; 889 people in the Maine filing | Japan disclosure |
| Access path | Fake Partner Central sites and stolen credentials | Compromise of a Blue Yonder system |
| Reported scale | 889 affected people in the Maine filing | Approximately 31,500 employees and former employees |
| Data profile | Names, Social Security numbers, dates of birth, and financial account and routing numbers were reportedly involved | Names and employee IDs, with limited additional information for about 50 people |
| Customer data | Starbucks said it was not affected | Starbucks Japan said customer data, addresses, contact information, salary, bank-account information and Japan’s national identification number were not involved |
Do not add the two incidents together or assume that the Blue Yonder data categories apply to the 2026 event.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Free protection first
Affected workers should use the Starbucks-provided Experian service and consider free freezes with all three nationwide credit bureaus before buying any commercial subscription. You can also obtain reports from AnnualCreditReport.com to look for unfamiliar accounts.
Paid identity-protection products may add household monitoring, restoration assistance or insurance, but they can duplicate the employer-funded benefit. No monitoring service guarantees prevention of identity theft, and monitoring does not replace a freeze or direct contact with your bank when account information is exposed.
Background and official sources
Starbucks’ general North America privacy notice explains its stated approach to personal-information processing but is not evidence about this incident. Its SEC filing discusses cybersecurity risks, including employee-data and third-party-provider risks, but is also not incident-specific.
The Bottom Line
The 2026 Starbucks incident was a targeted compromise of certain Partner Central accounts, affecting 889 people in the Maine filing—not a breach of Starbucks’ entire workforce or customer database. Treat the reported exposure of Social Security and financial-account information seriously: use the protection in your notice, consider credit freezes, scrutinize bank and payroll activity, and verify every follow-up message independently.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




