DisclosureLens
SINGAPOREUnknownHigh

STARBUCKS COFFEE SINGAPORE PTE. LTD.

bd_8428ae31e337ce1b · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Nov 10, 2023

To disclose

Affected

332,774

Confidence

90%
Full breach record for STARBUCKS COFFEE SINGAPORE PTE. LTD.

Regulator's decision — not a breach notification

This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.

Background On 13 September 2022, the Personal Data Protection Commission (the “ Commission ”) reached out to Starbucks Coffee Singapore Pte. Ltd. (the “ Organisation ”) after receiving information that personal data purporting to belong to the Organisation’s customers were available for sale online. The Organisation lodged a data breach notification to the Commission on 15 September 2022 and confirmed that its customer database, managed by its data intermediary, Ascentis Pte. Ltd. (“ Ascentis ”), was compromised by an unknown threat actor. As a result, the personal data of approximately 332,774 individuals including their names, phone numbers, email addresses, addresses, date of birth and membership information was compromised. Investigations revealed that the personal data breach could not be directly attributed to the Organisation but had occurred due to internal lapses on Ascentis’ end. Ascentis had engaged an overseas vendor, Kyanon Digital Co. Ltd (“ Kyanon ”) which was based in Vietnam, to complement and be part of the development team to assist in its project implementation for the Organisation. However, Ascentis failed to implement reasonable administrative and technical measures to ensure that Kyanon was in compliance with its IT policies and standards. Remedial Actions After the incident, as part of a remediation plan, the Organisation implemented the following: (a) Requested its vendor to implement two-factor authentication and IP address restriction to access the admin portal of the customer database; (b) Reset the application programming interface as a precautionary measure ; (c) Audited the processes of its vendor and require them to improve on its monitoring and security processes ; (d) Reviewed its existing contracts with 3 rd party vendors; and (e) Notified all affected customers . Undertaking T he Commission accepted the Undertaking as it was satisfi

Incident timeline — partial

? — ?

Breach window unknown

Nov 10, 2023

Filed

No linked breach filing · watching

Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • outcome + obligations
  • fine (SGD) and affected count where a grounds document states them
  • discovery date
  • notification clock

See the underlying breach notice, if any.

Starbucks Coffee Singapore Pte. LTD. — PDPA enforcement decision (2023) · DisclosureLens