VYPR
breachPublished Jul 20, 2026· 1 source

Threat Actor Claims Sale of 176 Million Starbucks User Records on Hacker Forum

A threat actor is allegedly selling a database containing 176 million Starbucks user records on a cybercrime forum, though the claims remain unverified.

A threat actor, operating under the handle "anes2010," has surfaced on a cybercrime forum, claiming to possess and offer for sale a database containing approximately 176 million unique Starbucks user records. The alleged data, reportedly exfiltrated in June 2026, includes a wide array of personal and account-specific information. Starbucks has not yet publicly confirmed the incident, and the authenticity of the claims and the dataset has not been independently verified.

The threat actor is reportedly asking for $400 for the database and has provided sample records to bolster the credibility of their claims. While sample data can lend an appearance of legitimacy, it does not confirm the overall accuracy, completeness, or origin of the entire dataset. According to intelligence shared by the account Intel and Breaches, the advertised database allegedly contains usernames, password hashes, email addresses, country and city details, account creation and last activity dates, and account status information.

Further details from the alleged listing suggest the inclusion of Starbucks Card details, including balances, auto-reload settings, preferred store locations, and even beverage preferences. The dataset purportedly also contains customer birthdays, loyalty program points, lifetime Stars accumulated, total spending figures, and currency information. If this data is indeed genuine and sourced from Starbucks, it could pose significant privacy risks and facilitate various fraudulent activities against affected customers.

The presence of password hashes is a key concern, though their actual risk depends heavily on the hashing algorithm used, the implementation of salts, and Starbucks' overall security practices. Weak hashing methods could potentially be vulnerable to offline cracking attempts. Moreover, the combination of email addresses and detailed loyalty program information makes customers prime targets for highly sophisticated phishing campaigns.

Attackers could leverage this data to craft convincing fraudulent communications related to reward points, account suspensions, gift card balances, or payment method updates, aiming to trick users into revealing credentials or financial details. Customers who reuse passwords across multiple online services are at a heightened risk, as any compromised Starbucks credentials could be tested against other accounts through credential stuffing attacks.

In light of these unverified claims, Starbucks customers are advised to exercise caution regarding unsolicited communications. It is recommended to avoid clicking on links in suspicious emails or messages and instead navigate directly to the official Starbucks website or mobile application. Users should ensure they are using a unique and strong password for their Starbucks account and refrain from reusing it elsewhere.

Customers should also remain vigilant in monitoring their Starbucks Card balances, loyalty program activity, stored payment methods, and any changes to their account profile for any signs of unauthorized access or suspicious activity. The full scope and veracity of the alleged data breach will require thorough investigation and confirmation by Starbucks and relevant cybersecurity organizations.

Synthesized by Vypr AI