Hacker Claims Starbucks Data Breach Involving 176 Million Records — What to Know

Hacker Claims Starbucks Data Breach Involving 176 Million Records — What to Know

A hacker claims 176 million Starbucks records were stolen and offered for sale. Here’s what customers should know, which details may be involved, and how to protect their accounts now. 

What Happened?

According to Cybersecurity News, a cybercrime forum user called “anes2010” claims to be selling a database linked to Starbucks customers.

The seller says the database contains 176 million unique records taken in June 2026. It was reportedly offered for $400, along with sample records.

However, samples do not prove that the full database is genuine, complete, or current.

Starbucks has not publicly confirmed the reported data breach. Independent researchers have also not verified where the information came from or whether it belongs to Starbucks customers.

If the records are genuine, criminals could use personal and account details to create convincing phishing emails, texts, or calls. These messages may mention reward points, Starbucks Card balances, or account problems.

It is also worth remembering that your information may have been leaked in other incidents without your knowledge. Checking for data leaks can help you find possible problems before criminals use the information against you.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who May Be Affected and What Data Could Be Involved?

The seller claims the records belong to Starbucks customers. However, no affected country, market, or customer group has been verified.

The claimed information includes email addresses, usernames, password hashes, cities, countries, account dates, account status, and email verification status.

The listing also reportedly mentions Starbucks Card details, balances, auto-reload settings, preferred stores, drink preferences, birthdays, Rewards points, and spending information.

However, no trusted source has confirmed that these fields are real or tied to 176 million unique people.

The source does not confirm whether full payment card numbers or security codes were included.

A password hash is a scrambled version of a password, rather than the readable password itself. Its safety would depend on the security method used.

If genuine, these details could help criminals create believable messages about rewards, balances, birthday offers, or auto-reload changes.

How the Claimed Starbucks Data Was Obtained

Technical details have not been shared publicly.

The seller says the records were taken in June 2026, but no access method has been verified.

The source does not say whether criminals used stolen passwords, a software weakness, an unsecured database, or another method.

Until Starbucks or independent investigators confirm the claim, the cause remains unknown.