• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechBest Companies

Hackers are Targetting the Starbucks App

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
May 13, 2017, 5:23 PM ET

Starbucks was one of the earliest retailers to aggressively promote payments via mobile phone, and their efforts have been wildly successful. A whopping 29% of Starbucks purchases are now made via the mobile app or online. That helps the retailer streamline the checkout process, track customer behavior, and provide coupons and other freebies.

But there’s an apparent downside for customers. Reports of scammers taking over Starbucks accounts with relative ease have circulated since at least 2015, and more are cropping up on social media daily, according to recent reports.

While there’s no indication Starbucks’ own servers have been compromised recently, lots of users recycle usernames and passwords from other services. The Starbucks app doesn’t use two-factor authentication—say, requiring a confirmation code sent by SMS—so a hacker who unearths a working username and password can simply pretend to be the user on another phone, in what’s known as an account takeover.

Get Data Sheet, Coins2Day’s technology newsletter.

That lets the hackers load funds into the Starbucks app from the victim’s credit card or bank account, and then the hackers spend that money. BuzzFeed’s Vanessa Wong (who, herself, was hacked to the tune of $100) pointed out in a recent story, noting a criminal can easily buy gift cards with a compromised account, and then sell those gift cards.

Starbucks told BuzzFeed that the level of fraud on the app is very low, describing it as “a tiny fraction of 1%.” They were similarly defensive in a statement to Good Housekeeping, pointing customers to a page outlining online security best practices—most importantly to “use different user names and passwords for different sites.”

That’s solid advice, but even a “tiny fraction of 1%” of customers getting hacked is still enough to generate a steady stream of customer angst.

Coins2Day contacted Starbucks for further comment, and will update this post upon response.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.