Starbucks fell back on manual payroll after Blue Yonder ransomware attack

Organization
Starbucks
Exploit
Supply Chain Attack
Industry
Food and Beverage Retail

A ransomware attack on Blue Yonder, the Panasonic-owned supply chain software vendor headquartered in Arizona, disrupted Starbucks' employee scheduling and time-tracking systems in late November 2024. Blue Yonder said the attack hit its managed services environment on November 21, 2024, disclosed the incident publicly later that week and brought in outside forensic experts. Starbucks confirmed the impact on its operations on Monday, November 25.

With the scheduling platform unavailable, managers at company-operated stores in the United States and Canada reverted to pen and paper to build schedules and record hours worked. Starbucks said it would pay employees for their scheduled shifts in the November 29 pay run, an approach that risked overpaying or underpaying staff whose actual hours, vacation or sick time differed from the schedule. The company said its priority was keeping its employees whole and that it would reconcile any differences once systems were restored.

Customer-facing operations were not affected. Starbucks said mobile ordering and in-store service continued as normal, and there was no indication that customer or employee data had been taken in the incident.

Blue Yonder gave no timeline for restoration. Other customers reported disruption as well, with UK grocers Morrisons and Sainsbury's affected and Morrisons falling back on backup systems for its fresh produce warehouse operations. Starbucks said it hoped the outage would not extend into later payroll cycles.

Sources