A threat actor named anes2010 claimed to sell 176 million unique Starbucks customer records on a dark web forum for 400 dollars in June 2026 just months after a confirmed Starbucks Partner Central phishing breach exposed employee credentials and sensitive personal data.
Imagine you walking into your favorite Starbucks location ordering your usual drink and then discovering that someone on a dark web forum sold your account details your email address your personal information and potentially your payment linked data to a stranger for less than the price of a week of coffee.
That scenario landed directly in front of the cybersecurity community when a threat actor using the handle anes2010 posted a forum thread titled Starbucks database for sale claiming to hold 176 million unique user records extracted in June 2026 and offering the entire dataset for just 400 dollars payable through Telegram contact.
Starbucks 176 Million Record Data Leak
The forum post published by anes2010 carries a timestamp of four hours before the screenshot circulated and describes a database containing 176 million unique user records extracted specifically in June 2026. The seller offered sample lines inside the post which were partially obscured in public screenshots but visible enough to confirm the dataset contained structured user data rather than random noise.

The asking price of 400 dollars represents an unusually low figure for a dataset claiming this size which either suggests the actor wants quick liquidity over maximum profit or wants to maximize distribution speed across multiple buyers simultaneously rather than selling to a single high value purchaser.
The timing of this claim lands against a documented backdrop of confirmed Starbucks security failures in early 2026. Between January 19 and February 11 2026 Starbucks suffered a confirmed breach targeting its Partner Central internal employee portal.
Threat actors used credential harvesting through phishing websites specifically designed to impersonate the legitimate Partner Central login page and successfully obtained employee login credentials during a three week unauthorized access window. Starbucks security teams detected the activity on February 6 and fully revoked attacker access by February 11.
A formal breach notification filed with the Maine Attorney General on March 10 2026 and submitted by Allison Sopko the Director of Privacy for North America at Starbucks Corporation confirmed the incident affected 889 individuals across multiple regions with five Maine residents specifically named.
That confirmed January breach exposed information including Social Security numbers and financial account details according to the Maine filing which classifies it as a high severity identity theft risk rather than a simple email leak.
Starbucks responded by offering affected individuals dark web surveillance credit monitoring identity restoration specialist access and up to one million dollars in identity theft insurance coverage with an enrollment deadline of June 30 2026.
The connection between the January confirmed breach and the June 2026 claimed 176 million record extraction requires careful analysis rather than automatic assumption of a direct link. The January breach targeted Partner Central which manages employee accounts while the June forum post claims 176 million unique user records suggesting customer data rather than purely employee data if accurate.
Two separate breach vectors operating against different systems during the same broad attack cycle against the same organization represents a pattern seen repeatedly in major retailer compromises where initial access through employee credential phishing enables broader lateral movement into customer facing databases.
The scale claimed by anes2010 deserves specific scrutiny. Starbucks reported approximately 40 million active Rewards members in recent years and the companys global customer base across all markets falls well below 176 million unique users depending on how user records get defined and whether duplicate or inactive accounts inflate the count.
A claimed dataset of 176 million against a realistic active customer base significantly smaller than that number raises questions about data composition that only forensic analysis of the actual sample lines could resolve. The figure could reflect historical records legacy account data merged datasets from multiple time periods or inflated counts designed to maximize perceived value.
Starbucks Customer Data Exposure Risk And Mitigation Guide
The anes2010 forum post follows a pattern that threat intelligence analysts recognize immediately. Low asking price combined with a massive claimed record count and a Telegram contact method rather than an escrow service represents a common tactic used by actors who want to establish reputation through volume sales rather than maximize return on a single transaction.
Selling a 176 million record database for 400 dollars effectively means selling it dozens of times over to different buyers each of whom then uses the data independently for credential stuffing phishing targeted scam campaigns or identity fraud operations.
The January 2026 breach specifically targeted Starbucks Partner Central accounts through credential harvesting techniques where threat actors directed victims to fraudulent phishing websites explicitly designed to impersonate the legitimate Starbucks Partner Central portal.
That attack surface sits in a completely different system tier from customer facing apps and rewards accounts yet both tiers now carry documented exposure events within the same six month window. GBHackers
Starbucks customers who hold active Rewards accounts or who have used the Starbucks mobile app with stored payment methods should treat this period as requiring heightened personal security attention regardless of whether the 176 million record claim gets independently verified.
The practical risk from unverified dark web claims remains real because even if the full dataset overstates its scope any legitimate portion of real customer records carries usable credentials for attacks against accounts where passwords get reused across multiple platforms.
The most immediate protective action for any Starbucks account holder involves changing the Starbucks app and website password to something completely unique that exists nowhere else in their digital life.
Enabling any available two step verification on the Starbucks account removes the primary attack vector that credential stuffing relies on since a password alone becomes insufficient even if it appears in a leaked dataset.
Monitoring linked payment methods for unexpected small transactions which attackers typically use to verify card validity before larger fraud attempts provides an early warning layer that can catch exploitation attempts before they escalate.
Organizations holding large consumer databases face a structural lesson from the Starbucks timeline. The gap between the January employee credential compromise and a June customer database extraction claim represents exactly the lateral movement window that security teams must monitor aggressively after any confirmed initial access event.
Revoking compromised credentials quickly as Starbucks did in February closes the original entry point but does not necessarily address artifacts the attacker left behind during the three week unauthorized access window before detection.
Dark web monitoring services that continuously scan known forums and markets for corporate data appearing in sale listings provide the earliest possible detection signal for this category of breach since forum posts often surface before any internal detection capability catches an ongoing extraction.
The anes2010 post appearing publicly represents the discovery phase for defenders rather than the beginning of the threat since the claimed June 2026 extraction suggests the data collection happened weeks before the public listing appeared.
For security professionals tracking this incident the forum handle anes2010 and the specific language of the listing including the exact phrase successfully extracted and the Telegram contact instruction represent attribution anchors that threat intelligence teams can cross reference against prior activity in other forums or markets to build a picture of whether this actor has a history of legitimate data sales or fabricated claims designed purely to collect 400 dollar payments from buyers who never receive usable data.
The broader Starbucks story across 2026 reflects a pattern hitting global consumer brands repeatedly throughout the year where a confirmed initial access event in the first quarter gets followed by increasingly serious claimed downstream consequences as attackers either return with additional access or sell original access to secondary actors who conduct their own deeper extraction campaigns against the same target infrastructure.