SHINDO4

Starbucks

Personal data~31,500people

LEAK CONFIRMEDUnauthorized access · Investigating

Open in the live monitor ▶
Disclosed
Sep 22, 2025
Leak
Leak confirmed
Type
Unauthorized access
Status
Investigating
Security spend
Not checked yet
Compensation
Not announced

What leaked

UnspecifiedEmployee personal data stored in the data transfer system

How many

  • Employees (provisional figure) ~31,500 people

Who is affected

  • Employees

Cause

Cyberattack on Blue Yonder, provider of the shift scheduling tool

Timeline

  1. Intrusion began
  2. Notified by Blue Yonder
  3. Sample data received
  4. Notice of additional data
  5. Further data provided
  6. First disclosure

Response

  • Notified individuals

What you should do

  1. Expect targeted phishing posing as HR or interview contacts
  2. Check the company's notice to see if you're affected

Lessons for companies

  1. Put security requirements, audit rights and reporting deadlines in vendor contracts
  2. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  3. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources