Caribou Coffee Co. disclosed Thursday that customers' credit card numbers and other security information may have been accessed as part of a data breach it first noticed on Nov. 30.
The company declined to say how many people were affected. In a notice posted on its website and sent to media organizations, Caribou Coffee listed 265 company-owned stores that were tied into the point-of-sale system that was attacked.
Most of the stores are in Minnesota, but the notice includes coffee shops in 10 other states.
Caribou said that customers who made a purchase with a credit or debit card between Aug. 28 and Dec. 3 may have had their name, credit card number, expiration date and security code stolen.
A letter from Caribou Coffee President John Butcher said the company reported the security breach to the FBI.
The company also is working with a leading cybersecurity firm to understand the scope of the incident, which explained the lag between when the breach was first discovered and when Caribou made an attempt to notify customers. The company said the investigation is ongoing.
Payments made through the Caribou Coffee Perks account or other loyalty accounts were not affected. Likewise not affected were catering orders placed online with sister brands under corporate owner JAB Holding Company: Bruegger's Bagels, Einstein Bros. Bagels, Manhattan Bagel and Noah's NY Bagels.
The company has set up a toll-free hotline at 1-877-698-3760, staffed Monday through Friday from 8 a.m. to 8 p.m. and weekends from 8 a.m. to 4 p.m. Consumers can also e-mail inquiries@cariboucoffee.com.