StarBucks Company (StarBucks.com
About the organisation
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
What the listing means
StarBucks Company (StarBucks.com appeared on the shadowbyt3$ leak site on 21 May 2026. Groups publish a victim once negotiations stall or as pressure during them, so a listing usually means data was already exfiltrated β the attack itself is dated 01 April 2026, 50 days before the listing. This group has not published new claims in the last 30 days.
Recommended actions
- Treat any unsolicited message referencing StarBucks Company (StarBucks.com as suspicious β leaked data gets weaponised for phishing within days.
- If you hold an account on Starbucks.com, change that password now, update it anywhere you reused it, and enable two-factor authentication.
- Other Hospitality and Tourism organisations should review this group's known TTPs and validate detection coverage against them.
- Watch for follow-on extortion: stolen data is often re-leaked or resold after the initial listing.
- A leak-site listing is a claim made by the attacker, not a confirmed breach β check the organisation's own disclosures before acting on it.
Leak-site evidence
Listing URL https://www.ransomware.live/id/U3RhckJ1Y2tzIENvbXBhbnkgKFN0YXJCdWNrcy5jb21Ac2hhZG93Ynl0MyQ...