271 million Uber Eats and Starbucks records surface on hacker forum: Should you be worried?
A silent malware can pump millions of records.

- Threat actors are selling alleged Uber Eats and Starbucks databases, but researchers suspect recycled infostealer logs.
- The listings claim 95 million Uber Eats records and 176 million Starbucks records are for sale.
- Cybernews researchers found sample users also appeared in June 2026 Stealer Logs or similar leaked datasets.
- The data may still endanger users because attackers can reuse stolen passwords across banking, work, and social accounts.
Two threat actors are advertising massive databases belonging to Uber Eats and Starbucks. However, Cybernews researchers point to infostealing malware.
Listings with claims recently appeared on a cybercrime marketplace offering 95 million alleged Uber Eats records and 176 million Starbucks records for sale.
The two listings were posted by different threat actors and contain different data samples. However, Cybernews researchers found that both datasets may have been collected via infostealing malware rather than through direct breaches of the companies.
The sample records appear to originate from a massive June 2026 stealer logs collection rather than pointing to fresh breaches.
For the alleged Uber Eats database, our researchers found that every sample user also appeared in the June 2026 Stealer Logs dataset and other known infostealer collections.
"The data seems to be legitimate, but all sample users are also present in the same or similar leaks. The seller has repeatedly advertised the same Uber Eats dataset, so it's difficult to verify whether this is actually a new breach," they said.
The Starbucks listing showed a similar pattern.
"Most of the sample users are also present in the June 2026 Stealer Logs or Data Troll Stealer Logs. It's very suspicious that multiple new 'breaches' all contain data from previously leaked stealer logs, although the individual records themselves appear genuine."
What is an infostealer?
Stealer logs are generated when malware infects an individual's computer and silently steals information stored in browsers, password managers, applications, and cryptocurrency wallets.
The June 2036 Stealer Logs, which may be the source of the data listed on hacker forums, are among the largest publicly available collections of credentials harvested by infostealer malware.
The dataset, containing hundreds of millions of records collected from infected devices, was added to the Have I Been Pwned database in June.
The dataset is alarmingly large, with more than 56 million unique email addresses and around 124 million unique passwords.
This means credentials for many different services can appear together in a single dataset, regardless of whether those companies were ever hacked.
Why are recycled stealer logs still dangerous?
Even if the listings do not originate from direct breaches of Uber Eats or Starbucks, the exposed credentials can still pose a significant threat.
“From an attacker's standpoint, if you have the full stealer leaks, it was a big dataset, you could try to brute-force or make a combo list, check which users are in other platforms, because users tend to reuse the same credentials," our researchers explained.
Password reuse remains one of the biggest security risks. If someone used the same email address and password across several services, attackers can automate login attempts against banking sites, social media accounts, corporate portals, or cloud services.
The risk extends beyond consumers.
"The same could also be done with administrator and management accounts."
Our researchers also noted that organizations sometimes share suppliers, authentication providers, or technology platforms.
"If major companies like Uber or Starbucks rely on a similar backend or third-party provider, a compromise there could potentially expose data affecting multiple organizations," our researchers explained.
“Just an idea, if you breach Uber, you would get client or employee info on Starbucks via Uber, due to the delivery platform.”
If you’ve recently used the services of Uber Eats or Starbucks, you should check if your credentials are among those breached.
How can your device be infected with an infostealer?
Unlike ransomware attacks, where attackers want to be seen extorting the victim, infostealers operate silently. The malware silently exfiltrates valuable data, which is later used to clear financial accounts or construct further attacks.
Victims often become infected by:
- Downloading pirated software or game cracks
- Installing fake software updates
- Opening malicious email attachments
- Clicking phishing links
- Installing trojanized browser extensions
- Running malware disguised as productivity tools
Once installed, infostealers search the device for anything that could be exploited. In the malware’s radar are saved passwords, browser cookies, or authentication tokens.
Loggers also scrape autofill information, go through cryptocurrency wallets, and messaging applications, to collect valuable data and send it to attackers' servers.
What to do if your device gets infected?
If you believe your device has been infected, you should take action to stay safe:
- Disconnect the affected device from the internet
- Run a reputable antivirus or endpoint security scan
- Use a trusted device to change passwords for email, banking platforms, and work accounts
- Enable multi-factor authentication wherever possible
- Review active login sessions and revoke unknown devices
- Monitor financial accounts and online services for suspicious activity
- If corporate credentials were stored on the infected device, notify your employer's security team immediately