DisclosureLens
HackingRetail & ConsumerRetailPhishingStolen CredentialsTargetedCustomer Data InvolvedIdentity (basic)Government IDFinancial accountMediumContained

STARBUCKS CORPORATION

bd_2ac8ff72f4ea44b3 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2026

Filed

Mar 12, 2026

To disclose

5 weeks

Affected · nationwide

8895 in this filing

Linked

8 filings

Confidence

66%
Full breach record for STARBUCKS CORPORATION3 incidents on file

Starbucks Corporation reported a data breach affecting 889 individuals, including 5 in Maine. Unauthorized access occurred between Jan 19 and Feb 11, 2026, via phishing impersonating Partner Central. Compromised data included names, SSNs, DOBs, and financial account numbers. Notices sent March 10, 2026.

Maine clockDiscovered Feb 6, 2026Filed with AG Mar 12, 202634d ME AG >30d5 weeks discovery → filing
AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.

Incident timeline

undetected · 18 days
discovery → filing · 5 weeks / 34 days

Jan 19, 2026

Begins

Feb 6, 2026

Discovered

Mar 12, 2026

Filed

vs. sector median

3 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (2)

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 2d gap

Filing propagation · 6 filings · 5 states

View merged incident ↗
Indiana State AGMar 10 · first
Indiana State AGMar 10 · first
Nebraska State AGMar 10 · first
Maine State AG+2d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.