Starbucks discloses data breach affecting hundreds of employees
嗯,用户让我用中文总结这篇文章,控制在一百个字以内,而且不需要用“文章内容总结”这样的开头。我得先仔细阅读文章内容,抓住关键点。 文章讲的是星巴克发生了数据泄露事件,影响了数百名员工。攻击者入侵了他们的Starbucks Partner Central账户。星巴克有超过38万名员工,在88个国家运营近4万家门店。他们在2月6日发现了这次事件,经过调查发现有889个账户被入侵,涉及员工的个人信息,包括社保号、出生日期、财务信息等。星巴克已经通知执法部门,并建议员工监控账户活动,还提供了两年的免费身份保护服务。此外,新加坡分部在2022年也发生过一起影响超过21.9万名顾客的数据泄露事件。 我需要把这些信息浓缩到100字以内。首先说明事件:星巴克数据泄露影响员工。然后提到入侵的是Partner Central账户,涉及个人信息如社保号、出生日期、财务信息。接着说明公司采取的措施:通知执法部门、提供保护服务,并提到之前也有类似事件。 这样组织起来应该能控制在100字左右。 </think> 星巴克发生数据泄露事件,影响数百名员工。攻击者入侵其Starbucks Partner Central账户,获取员工个人信息包括社保号、出生日期及财务信息。公司已通知执法部门,并为受影响员工提供两年免费身份保护服务。此前新加坡分部也曾发生类似数据泄露事件。 2026-3-13 08:30:20 Author: www.bleepingcomputer.com(查看原文) 阅读量:6 收藏

Starbucks

Starbucks has disclosed a data breach affecting hundreds of employees after threat actors gained access to their Starbucks Partner Central accounts.

As the world's largest coffeehouse chain, Starbucks has over 380,000 employees (also known as partners) and operates nearly 41,000 locations across 88 countries.

In data breach notification letters filed with Maine's Attorney General and sent to affected employees on Tuesday, the company says that it discovered the incident on February 6.

A joint investigation with external cybersecurity experts found that the attackers compromised 889 Starbucks Partner Central accounts used to manage employment details, personal information, benefits, and HR information.

Starbucks said the threat actors had access to affected individuals' accounts between January 19 and February 11, but didn't explain why it took five days to remove them from its systems.

"On or about February 6, 2026, Starbucks Corporation ('Starbucks' or 'we') became aware of potential unauthorized access to certain Starbucks Partner Central accounts," the company said. "The investigation has determined that an unauthorized third party accessed certain Starbucks Partner Central accounts after obtaining the login credentials through websites impersonating Partner Central."

The personal information exposed in the incident includes employees' names, Social Security numbers, dates of birth, and financial account and routing numbers.

Starbucks notified law enforcement agencies after discovering the breach and advised employees to monitor their bank accounts for suspicious activity that could indicate fraud or identity theft. The company is also providing impacted partners with two years of free identity theft protection and credit monitoring service through Experian IdentityWorks.

"Upon learning of the incident, we took prompt steps to investigate the nature and scope of the incident and respond to it," Starbucks added. "We also notified law enforcement and took measures to further strengthen security controls related to access to Starbucks Partner Central accounts."

BleepingComputer reached out to a Starbucks spokesperson with questions about the incident, but no immediate response was available.

Starbucks' Singapore division also confirmed a data breach affecting over 219,000 customers in September 2022, after a threat actor compromised the systems of a third-party vendor that stored the affected customers' data.

The coffee chain was also hit by the aftermath of a Termite ransomware attack that affected Blue Yonder (Starbucks' supply chain software provider) in November 2024.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/starbucks-discloses-data-breach-affecting-hundreds-of-employees/
如有侵权请联系:admin#unsafe.sh