2026 Starbucks — 889 employees (Partner Central phishing)
Data compromised
Names, SSNs, dates of birth, bank account and routing numbers
Technical writeup
Starbucks disclosed a data breach affecting 889 employees on March 13, 2026. Attackers created fake websites impersonating the Partner Central employee portal and phished employee credentials. Unauthorized access occurred January 19–February 11, 2026; discovered February 6. Exposed: names, Social Security numbers, dates of birth, bank account and routing numbers. Customer data not affected. Company offering 24 months identity protection via Experian IdentityWorks.
Root cause
Phishing; credential theft via fake Partner Central clone sites