Business & Tech

Are Thieves Hacking the Starbucks App?

The popular coffee chain acknowledges some users of mobile app are vulnerable, but the fault lies with password habits.

By BEA KARNES and CHARLENE ARSENAULT (Patch staff)

If you use a Starbucks app or gift card for payment and it’s linked to your credit card to automatically reload, you could be vulnerable to the latest hack attack.

Find out what's happening in Hartlandwith free, real-time updates from Patch.

But Starbucks says don’t blame the coffee chain, blame yourself for using the same password everywhere and for never changing those passwords.

Here’s how the scam works:

Find out what's happening in Hartlandwith free, real-time updates from Patch.

A hacker gains access to your gift card or app by simply entering the correct password and draining the balance by transferring the money to another Starbucks gift card. When the balance hits zero, it automatically reloads because it’s attached to your credit card. The thief can then drain the balance again, repeating as many times as they choose.

NBC News tells the story of Maria Nistri who lost the $34.77 balance from her card, and then had another $100 transferred from her credit card and stolen. The whole scam took just minutes.

“Occasionally, Starbucks receives reports from customers of unauthorized activity on their online account,” the statement read. “This is primarily caused when criminals obtain reused names and passwords from other sites and attempt to apply that information to Starbucks. To protect their security, customers are encouraged to use different user names and passwords for different sites, especially those that keep financial information.”

Remedy

  • Change your password
  • Disable auto-reload on your card or app

Several victims told CNNMoney they became aware of the fraud when they reived email confirmation that funds were being reloaded to their Starbucks accounts. One customer said the thief drained $115 from her bank account in a matter of a few seconds.

Cybersecurity firms are encouraging Starbucks to add authentication processes that ensure more security.

______________

Photo via Starbucks.com


Get more local news delivered straight to your inbox. Sign up for free Patch newsletters and alerts.