Social EngineeringRetail & ConsumerRetailPhishingStolen CredentialsMulti-Stage ChainData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
STARBUCKS CORPORATION
bd_2ac8ff72f4ea44b3 · schema v1 · pii pii-v1
Full breach record for STARBUCKS CORPORATION →Starbucks discovered Feb 6, 2026 that an external actor accessed Partner Central employee accounts via credentials stolen through phishing sites impersonating the portal (Jan 19–Feb 11, 2026). Exposed data: names, SSNs, DOBs, financial account/routing numbers. 889 total affected; 5 Maine residents. Law enforcement notified; access controls strengthened; 24-month Experian IdentityWorks offered.
Maine clockDiscovered Feb 6, 2026 → Filed with AG Mar 12, 202634d ⏱ ME AG >30d5 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_3f81392b7bd9141fIndiana State AGfiled 2026-03-10(2d gap)Candidate
- bd_4c209cf2fae846f1Indiana State AGfiled 2026-03-10(2d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/585e41ad-c38b-407c-8ce8-1f281d570d97.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 12, 2026
- Raw hash
- 4450ae88449eada2a5b0ba1714163257d985bf7ae9802a47df105b079936569a
Reporting entity
- Name
- STARBUCKS CORPORATIONnorm: starbucks
- Domain
- starbucks.com
- Industry
- Food & Beverage / Coffee Retail
Victim entity
- Name
- STARBUCKS CORPORATIONnorm: starbucks
- Domain
- starbucks.com
- Industry
- Food & Beverage / Coffee Retail
- Industry
- Retail & Consumerllm
Incident
- Discovered
- Feb 6, 2026
- Materiality determined
- —
- Notification sent
- Mar 10, 2026
- Affected individuals
- 5
- Data types
- PIIIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Law enforcement notified
- Initial access
- phishing_link
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- ME AG >30d · 34d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 6, 2026→ Filed with AG: Mar 12, 202634d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.