Starbucks: Threat Actors Allegedly Listed Starbucks Data on Hacker Forums

Starbucks: Threat Actors Allegedly Listed Starbucks Data on Hacker Forums

Starbucks Allegedly Targeted in Massive Data Breach Claim

A threat actor operating under the handle anes2010 has listed a claimed Starbucks database for sale on a cybercrime forum, alleging it contains 176 million unique user records reportedly extracted in June 2026. The seller is offering the dataset for $400 and has provided sample records to support the claim, though its authenticity remains unverified.

Starbucks has not confirmed the incident, and the breach claim has yet to be independently validated. According to threat intelligence sources, the alleged database includes:

  • Personal data: Email addresses, usernames, password hashes, location details (country/city), account creation dates, and activity logs.
  • Loyalty program details: Starbucks Card balances, auto-reload settings, preferred stores, beverage preferences, birthdays, Rewards points, lifetime Stars, and spending history.
  • Account metadata: Email verification status and currency information.

If genuine, the exposed data could pose significant privacy and fraud risks, enabling targeted phishing attacks, credential stuffing, or financial scams. While password hashes are not plaintext, their security depends on the hashing algorithm and implementation weak or outdated methods could allow offline cracking. The inclusion of loyalty program data may also facilitate highly personalized phishing campaigns, such as fake reward notifications or account suspension alerts.

The origin and full scope of the dataset remain unclear. Independent verification by Starbucks, cybersecurity researchers, or breach-monitoring organizations is needed to confirm the claim. As of now, the incident is treated as unconfirmed.

Source: https://cybersecuritynews.com/alleged-starbucks-data-breach/

Starbucks cybersecurity rating report: https://www.rankiteo.com/company/starbucks

"id": "STA1784543201",
"linkid": "starbucks",
"type": "Breach",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '176 million',
                        'industry': 'Food and Beverage',
                        'name': 'Starbucks',
                        'type': 'Corporation'}],
 'data_breach': {'data_encryption': 'Password hashes (algorithm unknown)',
                 'data_exfiltration': 'Alleged',
                 'number_of_records_exposed': '176 million',
                 'personally_identifiable_information': ['Email addresses',
                                                         'Usernames',
                                                         'Location details',
                                                         'Birthdays',
                                                         'Account creation '
                                                         'dates'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personal data',
                                              'Loyalty program details',
                                              'Account metadata']},
 'description': 'A threat actor operating under the handle *anes2010* has '
                'listed a claimed Starbucks database for sale on a cybercrime '
                'forum, alleging it contains 176 million unique user records '
                'reportedly extracted in June 2026. The dataset includes '
                'personal data, loyalty program details, and account metadata, '
                'posing significant privacy and fraud risks.',
 'impact': {'brand_reputation_impact': 'Potential significant impact',
            'data_compromised': '176 million unique user records',
            'identity_theft_risk': 'High',
            'legal_liabilities': 'Potential regulatory violations'},
 'initial_access_broker': {'data_sold_on_dark_web': 'Alleged'},
 'investigation_status': 'Unconfirmed',
 'motivation': 'Financial Gain',
 'references': [{'source': 'Cybercrime forum'}],
 'threat_actor': 'anes2010',
 'title': 'Starbucks Alleged Data Breach Claim',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.