STARBUCKS COFFEE SINGAPORE PTE. LTD.
bd_8428ae31e337ce1b · schema v1 · pii pii-v1
Full breach record for STARBUCKS COFFEE SINGAPORE PTE. LTD. →Regulator's decision — not a breach notification
This record is a regulator's decision, not the organisation's own breach notice. Breach-notification fields (discovery date, notification clock) are structurally absent — what this source establishes is the outcome and the provisions the decision cites.
Background On 13 September 2022, the Personal Data Protection Commission (the “ Commission ”) reached out to Starbucks Coffee Singapore Pte. Ltd. (the “ Organisation ”) after receiving information that personal data purporting to belong to the Organisation’s customers were available for sale online. The Organisation lodged a data breach notification to the Commission on 15 September 2022 and confirmed that its customer database, managed by its data intermediary, Ascentis Pte. Ltd. (“ Ascentis ”), was compromised by an unknown threat actor. As a result, the personal data of approximately 332,774 individuals including their names, phone numbers, email addresses, addresses, date of birth and membership information was compromised. Investigations revealed that the personal data breach could not be directly attributed to the Organisation but had occurred due to internal lapses on Ascentis’ end. Ascentis had engaged an overseas vendor, Kyanon Digital Co. Ltd (“ Kyanon ”) which was based in Vietnam, to complement and be part of the development team to assist in its project implementation for the Organisation. However, Ascentis failed to implement reasonable administrative and technical measures to ensure that Kyanon was in compliance with its IT policies and standards. Remedial Actions After the incident, as part of a remediation plan, the Organisation implemented the following: (a) Requested its vendor to implement two-factor authentication and IP address restriction to access the admin portal of the customer database; (b) Reset the application programming interface as a precautionary measure ; (c) Audited the processes of its vendor and require them to improve on its monitoring and security processes ; (d) Reviewed its existing contracts with 3 rd party vendors; and (e) Notified all affected customers . Undertaking T he Commission accepted the Undertaking as it was satisfi
P pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Nov 10, 2023
Filed
—
No linked breach filing · watching
Compliance clocks stay unassessable until a breach filing is linked. This record is the regulator's action, not a breach notice. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- outcome + obligations
- fine (SGD) and affected count where a grounds document states them
- discovery date
- notification clock
See the underlying breach notice, if any.