SHINDO2
Blue Yonder
Personal dataat least2organizations
LEAK CONFIRMEDHR / labour records / Full nameUnauthorized access · Investigating
Open in the live monitor ▶- Disclosed
- Sep 22, 2025
- Leak
- Leak confirmed
- Type
- Unauthorized access
- Status
- Investigating
- Security spend
- Not checked yet
- Compensation
- Not announced
What leaked
IdentityFull name
Employment & HREmployee ID, Employment category and attendance codes
Account dataHire date and work start date, Authority level
How many
- Japanese client companies that announced at least 2 organizations
- Starbucks employees ~31,500 people
- Seiyu employees and former employees 30,508 people
Who is affected
- Employees of client companies
- Former employees
Cause
A cyberattack on Blue Yonder leaked client companies' employee data stored in the data transfer system of its shift scheduling tool
Timeline
- Per Starbucks, the attack took place in December 2024
- Blue Yonder notified Starbucks
- Starbucks announced
- Seiyu announced
Response
- Notified individuals
- Vendor review
What you should do
- Expect targeted phishing posing as HR or interview contacts
- Check the company's notice to see if you're affected
Lessons for companies
- Put security requirements, audit rights and reporting deadlines in vendor contracts
- Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
- Run red teaming and AI-assisted hardening, and publish how much you invest
Sources
- Security NEXT News · Sep 22, 2025
- Security NEXT News · Nov 4, 2025