Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime Forum — Threadlinqs Intelligence
As of 2026-07-20, Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime Forum is a medium-severity data breach threat attributed to anes2010, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-1578 · Severity: MEDIUM · Status: TRACKING · Category: DATA_BREACH
Attribution: anes2010 · FINANCIAL
A threat actor using the handle 'anes2010' is advertising a database allegedly containing 176 million unique Starbucks customer records for $400 on a cybercrime forum, claiming emails, usernames,
On July 19, 2026, a threat actor operating under the handle 'anes2010' posted a listing on an undisclosed cybercrime forum offering a database of 176 million unique Starbucks user accounts for $400. The seller claims the data was extracted in June 2026 and includes email addresses, usernames, password hashes, city/country location data, account creation dates, account status, and email verification status, alongside Starbucks-specific fields: Starbucks Card balances, auto-reload preferences, preferred store/beverage preferences, birthdays, Starbucks Rewards points, lifetime Stars, and total spending history. The actor provided sample records to establish credibility, a common tactic on cybercrime marketplaces, though industry reporting is explicit that sample authenticity does not establish that a full dataset is genuine, current, or was obtained directly from the named organization.
As of this writing, Starbucks has issued no public confirmation of the incident, and no independent forensic validation of the dataset's authenticity, completeness, or direct sourcing from Starbucks systems has been published. No CVE, exploited vulnerability, or confirmed initial-access vector has been identified or attributed to this specific listing.
Secondary reporting introduces a credible alternative explanation: cybernews researchers examining a related, contemporaneous claim of 271 million combined Uber Eats and Starbucks records concluded the underlying data may have been aggregated from mass infostealer ('stealer log') collections harvested from infected consumer endpoints — i.e., credentials and session data siphoned by malware such as RedLine, Raccoon, Lumma, or similar commodity infostealers when users logged into the Starbucks mobile app or website on compromised devices — rather than exfiltrated via a direct compromise of Starbucks' backend infrastructure. This would mean the 'breach' framing may be a mischaracterization of a credential-stuffing/stealer-log aggregation event, a pattern increasingly common in 2025-2026 dark-web listings that bundle scattered infostealer logs under a single high-profile brand name to increase resale value and buyer interest.
The listing occurs against a backdrop of a genuinely turbulent 2026 threat landscape for Starbucks: the company confirmed a separate, verified breach in which a phishing/social-engineering attack against an employee of a third-party business partner compromised the Partner Central portal between January 19 and February 11, 2026, exposing personal and financial data of 889 individuals. Separately, in early April 2026 extortion actors (reported under the handles 'Shadowbyt3$' and 'BlackVortex1' across different outlets, likely the same underlying incident or closely coordinated campaigns) posted on DarkForums.su claiming compromise of Starbucks operational technology — including Mastrena II espresso machine control logic, beverage dispenser firmware (.hex binaries), the Global Management UI source code, JavaScript bundles exposing API endpoints, source maps, and developer backup folders potentially containing credentials — demanding a $500,000 ransom with an April 5, 2026 deadline. Older, confirmed incidents include a 2022 breach of Starbucks Singapore affecting roughly 220,000 customers, and Starbucks' downstream exposure to the November 2024 Termite ransomware attack against supply-chain software provider Blue Yonder.
Taken together, this listing must be tracked as an UNVERIFIED claim pending confirmation from Starbucks, but it sits inside a real pattern of repeated targeting of the Starbucks brand and its customer/loyalty ecosystem by financially motivated actors across 2022-2026, spanning credential-based consumer data claims, confirmed partner-portal phishing compromise, supply-chain ransomware fallout, and OT/source-code extortion.
Target sectors: retail, food-and-beverage, hospitality
Target regions: North America, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, MEDIUM, threat intelligence, cybersecurity, T1583, T1588, T1586, T1566, T1078, T1555, T1539, T1552, T1213, T1005