Starbucks Investigates Alleged Data Breach of 176 Million Records

Starbucks is currently investigating claims that a threat actor, identified as “anes2010,” has listed a database purportedly containing 176 million unique user records for sale on a cybercrime forum. The data, allegedly extracted in June 2026, is being offered for $400, with sample records provided to substantiate the claim.

The alleged dataset reportedly includes sensitive customer information such as email addresses, usernames, password hashes, country and city details, account creation and last activity dates, account status, and email verification status. Additionally, it is claimed to contain Starbucks Card details and balances, auto-reload settings, preferred stores, beverage preferences, birthdays, Starbucks Rewards points, lifetime Stars, total spending, and currency information.

At this time, Starbucks has not publicly confirmed any security incident, and the authenticity of the alleged data breach remains unverified. The company is conducting a thorough investigation to determine the validity of these claims.

If the breach is confirmed, the exposure of such comprehensive customer data could pose significant privacy and security risks. Password hashes, depending on the hashing algorithm used, could potentially be cracked, leading to unauthorized access to user accounts. The detailed personal and loyalty program information could also be exploited for targeted phishing campaigns, aiming to deceive customers into revealing further sensitive information.

Customers are advised to remain vigilant for any suspicious communications claiming to be from Starbucks, especially those requesting personal information or urging immediate action. It is recommended to access Starbucks services directly through official channels, such as the company’s website or mobile app, rather than through links provided in unsolicited messages.

To enhance account security, customers should use strong, unique passwords for their Starbucks accounts and avoid reusing passwords across multiple platforms. Monitoring account activity, including Starbucks Card balances and rewards points, for any unauthorized changes is also advisable.

As the investigation continues, Starbucks is expected to provide updates and guidance to its customers. This incident underscores the critical importance of robust cybersecurity measures and proactive monitoring to protect sensitive customer information in the digital age.