Starbucks sued after laptop data breach

By Robert McMillan, IDG News Service |  Security, data breach, privacy 2 comments

A Chicago-area Starbucks employee has brought a class-action lawsuit against the coffee retailer, claiming damages from an October 2008 data breach.

Laura Krottner was one of 97,000 employees notified late last year after a Starbucks laptop containing employee names, addresses and Social Security numbers was stolen on Oct. 29. Krottner's suit accuses the company of fraud and negligence.

The lawsuit was filed Thursday in federal court in Seattle. Starbucks has offered employees one-year's free credit monitoring and protection, but Krottner is asking the court to extend that to five years. She is also seeking unspecified damages and asking that Starbucks be ordered to submit to periodic security audits of its computer systems.

"Starbucks failed to follow reasonable precautions to secure its employees' [personally identifiable information], failed to provide timely notice, and failed to protect employees from invasion of privacy, fraud, identity theft, and associated expenses," court filings state, adding that Krottner and the other employees must now spend "considerable time and money to protect themselves," from identity theft.

The company was unable to immediately comment on the lawsuit, but it said it has seen no fraud linked to the incident, according to its breach notification letter.

Lately, however, chatter on some Starbucks message boards shows that there have been some ID theft victims as a result of the incident, the lawsuit states.

News of the lawsuit was first reported Saturday on the Spam Notes blog written by Venkat Balasubramani, the principal with Balasubramani Law.

The suit is the latest of several in which plaintiffs are trying to prove that data breaches are harmful, even if they do not result in identity theft, Balasubramani said in an interview Monday. Courts in Arkansas and Indiana have rejected similar claims in recent years, he noted.

The plaintiffs in the Starbucks case, who are seeking a jury trial, may have better luck, however. "Washington could be different," he said. "I think Washington is viewed as a privacy friendly state."

Late last month the U.S. Department of Veterans Affairs reached a US$20 million settlement with plaintiffs in a class-action suit seeking damages following the 2006 theft of a laptop and hard drive containing data on 26.5 million veterans. According to reports, veterans who can show harm related to the theft will be paid between $75 and $1,500.

Starbucks has lost laptops before. In November 2006, the company reported that it had lost two laptops containing the Social Security numbers of nearly 60,000 current and former employees.

2 comments

    Anonymous 2 years ago
    I was very happy that I found the antispyware solution from Search-and-destroy (http://www.Search-and-destroy.com) to help me rid my PC from the bugs that threaten its overall performance. I’m sure that you already know that when you search the wide world of cyberspace you pick up spyware and viruses that can make your computer run slow and sluggish. Over time, it will completely stop working if you don’t find a good scan to prevent this from happening and the Search-and-destroy Antispyware is one of the best I’ve found so far. I love it and I’m sure you will too.
    mburton325
    mburton325 2 years ago
    Why is this information being kept on an unsecure Laptop and not on a secured server?Would love to hear the answer to this one.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Answers - Powered by ITworld

      Ask a question

      Ask a Question