Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime Forum
Alleged Starbucks Data Breach (TL-2026-1578) is a medium-severity data breach, first published 2026-07-20. It has no confirmed attribution, affects Starbucks Corporation Starbucks Rewards / Starbucks Card customer, maps to 18 MITRE ATT&CK techniques (T1005, T1078, T1119), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-1578
- Threat ID
- TL-2026-1578
- Severity
- MEDIUM
- Status
- TRACKING
- Category
- DATA_BREACH
- First published
- 2026-07-20
- Last reviewed
- 2026-07-20
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, food-and-beverage, hospitality
- Target regions
- North America, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Alleged Starbucks Data Breach
Malware and tooling: Lumma Stealer - S1213, Raccoon Stealer - S1148, RedLine Stealer - S1240, Vidar Stealer
A threat actor using the handle 'anes2010' is advertising a database allegedly containing 176 million unique Starbucks customer records for $400 on a cybercrime forum, claiming emails, usernames, password hashes, loyalty/rewards data, and Starbucks Card balance/auto-reload details extracted in June 2026. Starbucks has not confirmed the incident; researchers note the sample data may originate from mass infostealer 'stealer log' collections rather than a direct breach of Starbucks infrastructure.
How Alleged Starbucks Data Breach works
On July 19, 2026, a threat actor operating under the handle 'anes2010' posted a listing on an undisclosed cybercrime forum offering a database of 176 million unique Starbucks user accounts for $400. The seller claims the data was extracted in June 2026 and includes email addresses, usernames, password hashes, city/country location data, account creation dates, account status, and email verification status, alongside Starbucks-specific fields: Starbucks Card balances, auto-reload preferences, preferred store/beverage preferences, birthdays, Starbucks Rewards points, lifetime Stars, and total spending history. The actor provided sample records to establish credibility, a common tactic on cybercrime marketplaces, though industry reporting is explicit that sample authenticity does not establish that a full dataset is genuine, current, or was obtained directly from the named organization.
As of this writing, Starbucks has issued no public confirmation of the incident, and no independent forensic validation of the dataset's authenticity, completeness, or direct sourcing from Starbucks systems has been published. No CVE, exploited vulnerability, or confirmed initial-access vector has been identified or attributed to this specific listing.
Secondary reporting introduces a credible alternative explanation: cybernews researchers examining a related, contemporaneous claim of 271 million combined Uber Eats and Starbucks records concluded the underlying data may have been aggregated from mass infostealer ('stealer log') collections harvested from infected consumer endpoints — i.e., credentials and session data siphoned by malware such as RedLine, Raccoon, Lumma, or similar commodity infostealers when users logged into the Starbucks mobile app or website on compromised devices — rather than exfiltrated via a direct compromise of Starbucks' backend infrastructure. This would mean the 'breach' framing may be a mischaracterization of a credential-stuffing/stealer-log aggregation event, a pattern increasingly common in 2025-2026 dark-web listings that bundle scattered infostealer logs under a single high-profile brand name to increase resale value and buyer interest.
The listing occurs against a backdrop of a genuinely turbulent 2026 threat landscape for Starbucks: the company confirmed a separate, verified breach in which a phishing/social-engineering attack against an employee of a third-party business partner compromised the Partner Central portal between January 19 and February 11, 2026, exposing personal and financial data of 889 individuals. Separately, in early April 2026 extortion actors (reported under the handles 'Shadowbyt3$' and 'BlackVortex1' across different outlets, likely the same underlying incident or closely coordinated campaigns) posted on DarkForums.su claiming compromise of Starbucks operational technology — including Mastrena II espresso machine control logic, beverage dispenser firmware (.hex binaries), the Global Management UI source code, JavaScript bundles exposing API endpoints, source maps, and developer backup folders potentially containing credentials — demanding a $500,000 ransom with an April 5, 2026 deadline. Older, confirmed incidents include a 2022 breach of Starbucks Singapore affecting roughly 220,000 customers, and Starbucks' downstream exposure to the November 2024 Termite ransomware attack against supply-chain software provider Blue Yonder.
Taken together, this listing must be tracked as an UNVERIFIED claim pending confirmation from Starbucks, but it sits inside a real pattern of repeated targeting of the Starbucks brand and its customer/loyalty ecosystem by financially motivated actors across 2022-2026, spanning credential-based consumer data claims, confirmed partner-portal phishing compromise, supply-chain ransomware fallout, and OT/source-code extortion.
MITRE ATT&CK techniques used in TL-2026-1578
Collection
T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories
Initial Access
T1078 Valid Accounts; T1566 Phishing
Discovery
Exfiltration
T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Impact
T1565 Data Manipulation; T1657 Financial Theft
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1588 Obtain Capabilities
Reconnaissance
T1594 Search Victim-Owned Websites; T1596 Search Open Technical Databases
Affected products and versions in Alleged Starbucks Data Breach
- Starbucks Corporation — Starbucks Rewards / Starbucks Card customer accounts (mobile app and web)
Vulnerable versions: Consumer accounts allegedly extracted June 2026
Remediation for Alleged Starbucks Data Breach
Immediate actions
- Starbucks Rewards/loyalty account holders should proactively rotate account passwords and enable multi-factor authentication where available.
- Monitor Starbucks Card balances and auto-reload payment methods for unauthorized transactions or balance drains.
- Treat unsolicited emails/SMS referencing Starbucks Rewards, gift card balances, or account verification with heightened scrutiny pending confirmation of the breach.
- Do not reuse the password associated with any Starbucks account on other services; if reused, rotate it everywhere.
- Enterprises should flag internal traffic to known infostealer log marketplaces and cybercrime forums referenced in this listing.
Workarounds
- Until Starbucks confirms or denies the incident, treat any Starbucks account credentials as potentially exposed and apply defense-in-depth (MFA, unique passwords, payment monitoring) rather than waiting on official confirmation.
Longer-term hardening
- Deploy endpoint detection focused on commodity infostealer malware families (RedLine, Raccoon, Lumma, Vidar) given the suspected stealer-log origin of similar large-brand data listings.
- Implement credential-stuffing and anomalous-login detection on consumer-facing loyalty/rewards platforms.
- Establish dark-web/underground-forum monitoring for brand-name mentions to shorten detection-to-confirmation time for future claims.
- Harden third-party/business-partner portal access (lesson from the confirmed Jan-Feb 2026 Partner Central phishing compromise) with phishing-resistant MFA.
Timeline of Alleged Starbucks Data Breach
- Starbucks Singapore suffers a data breach affecting approximately 220,000 customers (earliest confirmed Starbucks customer-data incident in this pattern).
- Termite ransomware attack against supply-chain software provider Blue Yonder disrupts operations for downstream customers including Starbucks.
- Confirmed phishing/social-engineering attack begins against a Starbucks business partner employee with access to the Partner Central portal.
- Confirmed Partner Central compromise window closes; personal and financial data of 889 individuals confirmed exposed. Starbucks later discloses this incident publicly.
- Extortion actor(s) reported as 'BlackVortex1'/'Shadowbyt3$' post on DarkForums.su claiming compromise of Starbucks operational technology (Mastrena II espresso machine firmware, Global Management UI source code, API endpoints), demanding $500,000 with an April 5, 2026 deadline.
- Threat actor 'anes2010' claims the 176-million-record customer database was extracted from Starbucks around this date (exact date unconfirmed).
- A related/contemporaneous cybercrime-forum listing offers a combined 271 million Uber Eats and Starbucks records; researchers assess the data likely originates from mass infostealer stealer-log collections rather than a direct company breach.
- 'anes2010' posts the 176-million-record Starbucks database listing for $400 on an undisclosed cybercrime forum, including sample records.
- TL-Intel-Harness ingests the claim via RSS hunt phase and opens TL-2026-1578 for tracking as an unverified breach claim.
- Cyber Security News, Cybernews, Futureproof, and other outlets report on the unverified claim; Starbucks has not issued a public confirmation or denial.
Sources cited for Alleged Starbucks Data Breach
- Threat Actors Allegedly Listed Starbucks Data on Hacker Forums
- Hackers claim Starbucks data breach, but researchers are not so sure
- Infostealers to blame? Hackers claim 271 million Uber Eats and Starbucks records are up for sale
- Starbucks Data Breach: 176M Records Reportedly Stolen — What to Know
- Starbucks: 176 million accounts allegedly leaked
- Starbucks Confirms Data Breach from a Social Engineering Attack on a Business Partner
- Starbucks Data Breach Allegation: Key Risks Revealed
- Inside the Starbucks breach trilogy
- Starbucks Data Breach Impacts Employees
Threats related to Alleged Starbucks Data Breach
- OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin Stolen
- KDDI Zero-Day Exploit in Third-Party Software Exposes Up to 14.2 Million Email Accounts at Six Japanese ISPs (STNet, JCOM, Chubu Telecommunications, NIFTY, BIGLOBE, KDDI Web Communications)
Detection coverage for TL-2026-1578
As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1578 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.