SHINDO2

Blue Yonder

Personal dataat least2organizations

LEAK CONFIRMEDHR / labour records / Full nameUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Sep 22, 2025
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name
Employment & HREmployee ID, Employment category and attendance codes
Account dataHire date and work start date, Authority level

How many

  • Japanese client companies that announced at least 2 organizations
  • Starbucks employees ~31,500 people
  • Seiyu employees and former employees 30,508 people

Who is affected

  • Employees of client companies
  • Former employees

Cause

A cyberattack on Blue Yonder leaked client companies' employee data stored in the data transfer system of its shift scheduling tool

Timeline

  1. Per Starbucks, the attack took place in December 2024
  2. Blue Yonder notified Starbucks
  3. Starbucks announced
  4. Seiyu announced

Response

  • Notified individuals
  • Vendor review

What you should do

  1. Expect targeted phishing posing as HR or interview contacts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources