Hackers Claim 176 Million Starbucks Records Are for Sale


A threat actor using the name “anes2010” claims to be selling a database containing 176 million Starbucks user records. The alleged database appeared on a cybercrime forum with a reported price of $400.

Starbucks has not publicly confirmed that its customer systems were breached. No independent security researcher or breach-monitoring organization has publicly validated the full database, its source, or the number of unique people it allegedly contains as of July 20, 2026.

The allegation gained attention after the threat intelligence account Intel and Breaches reported the Starbucks listing. Until stronger evidence emerges, the incident should be described as an unverified data-sale claim rather than a confirmed Starbucks data breach.

What the Threat Actor Claims

The seller claims that the database was extracted in June 2026 and contains 176 million unique user records. The advertisement reportedly includes sample data intended to support the sale.

A separate VECERT forum intelligence listing also identifies Starbucks, the “anes2010” handle and the claimed record count. Such threat intelligence entries document what actors advertise, but they do not automatically verify the accuracy of those advertisements.

The alleged information spans account details, location data, Starbucks Rewards activity and Starbucks Card information. Every category remains part of the seller’s claim and should not be treated as confirmed exposure.

Allegedly offered dataPotential risk if authentic
Email addresses and usernamesPhishing, account identification and credential-stuffing attempts
Password hashesOffline password-cracking attempts, depending on the hashing method
Country, city and preferred storeLocation-based phishing and customer profiling
Birthdays and account datesIdentity verification abuse and personalized scams
Starbucks Card balances and auto-reload settingsStored-value fraud and convincing payment-themed messages
Rewards points and lifetime StarsLoyalty-account takeover and fraudulent redemption
Purchase totals and beverage preferencesHighly personalized impersonation campaigns

Why the 176 Million Figure Remains Unverified

Cybercrime forums contain genuine stolen databases, recycled leaks, fabricated listings and data assembled from unrelated sources. A large number in a sales post does not show how many records exist, whether they are unique, or whether they came directly from the company named in the advertisement.

A dataset may also contain duplicates, test accounts, outdated profiles or records compiled from earlier breaches. Sellers sometimes attach a prominent brand to aggregated data to increase its value.

The seller’s samples would need to undergo controlled validation. Investigators would look for internal consistency, recent account activity, non-public fields and evidence connecting the records to Starbucks systems. Publicly exposing additional personal data during that process could harm the people represented in the sample.

  • The complete database has not been made available for independent examination.
  • The alleged June 2026 extraction date has not been verified.
  • The method used to obtain the data remains unknown.
  • The 176 million figure may not represent unique individuals.
  • No public technical evidence currently ties the listing to a compromised Starbucks system.
  • Starbucks has not confirmed the claimed customer-data incident.

Claims About Starbucks Rewards and Card Data

The forum advertisement allegedly includes Starbucks Card balances, auto-reload settings, Rewards points, lifetime Stars and spending information. If authentic, those fields could help criminals create persuasive messages about account balances, reward expirations or payment problems.

Starbucks describes the types of information it may process in its privacy notice, including account login information and data used to provide store and ordering services. The privacy notice does not prove that any of this information was stolen.

Similarly, the presence of fields that resemble real Starbucks services does not authenticate the database. A seller can copy public field names, combine previously exposed customer information, or generate realistic-looking sample entries.

Password Hashes Are Not Plaintext Passwords

The seller claims that password hashes are included. A password hash is a derived value used to check a password without storing the original password in readable form.

The practical risk depends on the algorithm, configuration and use of unique salts. Modern, slow password-hashing methods can make cracking expensive. Weak or outdated algorithms may allow attackers to test large password lists offline and recover some passwords.

Even without recovering passwords, email addresses and usernames can support account takeover attempts. Criminals may test credentials stolen in unrelated breaches against Starbucks and other online services, a technique known as credential stuffing.

Account conditionLikely risk
Unique password used only for StarbucksLower risk to unrelated accounts
Same password reused elsewhereHigher risk of credential stuffing across multiple services
Weak or common passwordHigher risk of guessing or offline cracking
Unexpected password-reset messages receivedPossible phishing or account-probing activity
Stored Starbucks Card balance presentPotential financial loss if the account is taken over

Phishing Is the Most Immediate Customer Risk

An unverified breach claim can still create opportunities for scammers. Public discussion gives criminals a timely pretext for messages claiming that Starbucks accounts require password resets, payment verification or urgent security checks.

The Federal Trade Commission’s phishing guidance warns that fraudulent messages commonly impersonate familiar companies and claim that an account or payment method has a problem. Their purpose is to pressure recipients into clicking a link or disclosing information.

The reported forum advertisement lists data that could make these messages more convincing. A scammer who knows a person’s city, preferred store or approximate rewards activity could create a message that appears tailored to the recipient.

  • Messages claiming that Rewards points will expire immediately
  • Alerts about a suspended Starbucks account
  • Requests to confirm an auto-reload payment method
  • Offers to restore a missing Starbucks Card balance
  • Fake refunds, surveys or promotional rewards
  • Password-reset links sent without a customer request

What Starbucks Customers Should Do

Customers do not need to wait for a breach confirmation to improve account security. Anyone who reused a Starbucks password on another service should replace it with a unique password, starting with email, financial and retail accounts.

Customers should access their accounts through the official Starbucks application or by entering the company’s website address directly. The FTC’s anti-phishing recommendations advise users not to click links or open attachments in unexpected messages, even when the message appears to come from a known company.

Users with stored Starbucks Card value should review recent transactions and current balances. The official Starbucks Card terms explain how customers can check transaction history and report a registered card as lost, stolen or compromised.

  1. Change the Starbucks password if it is reused, weak or old.
  2. Use a password manager to create and store a unique password.
  3. Check Starbucks Card balances and recent transactions.
  4. Review Rewards points and account profile information for unexpected changes.
  5. Remove stored payment methods that are no longer needed.
  6. Do not use password-reset links from unsolicited emails or text messages.
  7. Contact Starbucks through an official channel if suspicious activity appears.
  8. Change reused passwords on other services, especially the associated email account.

How Customers Can Report Suspicious Card Activity

Registered Starbucks Cards can receive some protection after a customer reports them missing or compromised. Starbucks says it can freeze the balance remaining at the time of notification and transfer that value to a replacement card, subject to its terms.

Customers should act quickly because Starbucks treats its cards like cash. The company’s card and balance guidance says customers can review recent transactions online and contact customer service to dispute a transaction or correction.

The company’s Starbucks privacy notice also provides information about its data practices and customer privacy rights. It should be consulted through the official website rather than through a link in an unexpected security message.

What Evidence Would Confirm the Alleged Breach?

Confirmation could come from Starbucks, a regulatory filing, customer breach notifications, a law enforcement statement or independent technical validation. Investigators may also identify a compromised system, stolen credentials, access logs or other evidence showing how the data left Starbucks-controlled infrastructure.

The forum-monitoring record confirms that the claim was observed, not that the advertised database is genuine. This distinction matters because reporting an alleged sale as a verified compromise can mislead customers and amplify a criminal seller’s marketing.

For now, the responsible conclusion remains limited: a threat actor claims to possess 176 million Starbucks records, but the database, its source and its scale remain unconfirmed. Customers should stay alert for phishing and account fraud while waiting for authoritative findings.

FAQ

Was Starbucks breached in June 2026?

A threat actor claims to have extracted Starbucks data in June 2026, but Starbucks has not confirmed the incident. The alleged database and its origin have not been independently validated.

Did hackers steal 176 million Starbucks customer records?

The 176 million figure comes from a cybercrime forum advertisement. It has not been verified, and it is unknown whether the records exist, are unique, are current or came directly from Starbucks.

What information is allegedly in the Starbucks database?

The seller claims it contains emails, usernames, password hashes, location details, account dates, Starbucks Card information, Rewards points, spending data and customer preferences. None of these claimed data categories has been independently confirmed.

Should Starbucks customers change their passwords?

Customers should change their password if it is weak, old or reused on another service. A unique password limits the damage from credential stuffing even when a breach claim remains unverified.

How can Starbucks customers avoid related phishing scams?

Customers should avoid links in unexpected emails and text messages. They should open the official Starbucks application or enter the company website directly to check balances, rewards, transactions and account alerts.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages