Early access: the directory is still filling out, and every rating here is a reported experience.
NR Unrated
Starbucks
Starbucks HackerOne
2 more reviews needed for a grade
Write a review Claim this company profile

Work at Starbucks? Claim it to respond to reviews as the verified owner.

Found a vulnerability?

If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.

Ask BugRater to submit it

Private. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.

Program metrics HackerOne · published

HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 5 Oct 2026.

What it pays, by severity

Critical amount not published 187 reports
High $605 avg 381 reports firm
Medium $583 avg 1,014 reports firm
Low $125 avg 391 reports firm

$1,350,000 paid to researchers in total, $10,000 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.

Intake & responsiveness · last 90 days

Reports received
69
in 90 days
Resolved
2,096
all time, last one 2 days ago
Participants
1,374
hunters engaged
Response efficiency
80%
meeting its targets, HackerOne’s figure
SLA misses
0
targets missed
Reports received · day by day, last 18 days 62–72
6 Sep 69 reports 5 Oct

Response targets it sets itself

First response
1 day
Triage
10 days
Bounty
30 days
Resolution
4 days

A target the program declared, not a measurement of it being met.

Getting in the door

bounty amounts hidden

Over 46 days (121 snapshots): intake down 6 reports; response efficiency up 9 points; 90-day payout up $5,000.

See how this programme’s report load compares to others →

Reviews

1 published
Hacktivity: Starbucks (100 disclosed)
★★★★★ neutral

Source: HackerOne Hacktivity (public disclosures) Program: https://hackerone.com/starbucks Disclosed reports analyzed: 100 Bounties: none in disclosed reports --- Aggregated from publicly disclosed HackerOne reports. Ratings derived from triage timing and bounty data.

via HackerOne reports 100
Anonymous researcher · Oct 1, 2026 · Share ↗ 0 helpful
0 comments

Log in to comment

Who this program credits

1,421 credited

Researchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.

# Researcher Reputation Recognised / submitted
1 def1ant 1,334 40 / 57 70%
2 godiego 1,265 65 / 79 82%
3 meals 1,263 52 / 61 85%
3 b006e4ea768a5d1b5340969 640 24 / 31 77%
4 spaceraccoon 946 44 / 46 96%
5 0xmzm 933 36 / 59 61%
6 todayisnew 689 45 / 72 63%
7 arneswinnen 648 15 / 15 100%
8 melar_dev 532 21 / 23 91%
9 mikee 508 28 / 50 56%
10 jskiba 507 31 / 37 84%
11 bebiks 506 12 / 15 80%
12 0xpatrik 468 14 / 14 100%
12 linkks 287 32 / 59 54%
13 bayotop 449 17 / 18 94%
14 badf00d 434 21 / 23 91%
15 proabiral 387 17 / 19 89%
16 k3mlol 360 23 / 43 53%
17 txt3rob 356 10 / 13 77%
18 nishant57 353 14 / 17 82%
19 shubs 342 11 / 11 100%
20 xandsz 312 17 / 32 53%
21 m0chan 298 19 / 40 48%
22 damian89 290 16 / 20 80%
23 theokeen 273 15 / 18 83%

Showing the top 25 of 1,421 credited on HackerOne.

Program profile HackerOne · imported

Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 30 Sep 2026.

Premier purveyor of the finest coffee in the world, inspiring and nurturing the human spirit — one person, one cup and one neighborhood at a time.

Responsiveness
81% HackerOne’s figure
Swag
No
Currency
USD
Submissions
Open
Launched
Nov 2016
Scope entries
47 HackerOne’s count

Scope

43 assets
AssetTypeEligibilityMax severity
app.starbucks.com URL ✓ bounty Critical
card.starbucks.com.sg URL ✓ bounty Critical
cart.starbucks.co.jp URL ✓ bounty Critical
com.starbucks.br APPLE STORE APP ID ✓ bounty Critical
com.starbucks.cn GOOGLE PLAY APP ID ✓ bounty Critical
Show all 43 assets
AssetTypeEligibilityMax severity
com.starbucks.de APPLE STORE APP ID ✓ bounty Critical
com.starbucks.fr APPLE STORE APP ID ✓ bounty Critical
com.starbucks.jp APPLE STORE APP ID ✓ bounty Critical
com.starbucks.mobilecard GOOGLE PLAY APP ID ✓ bounty Critical
com.starbucks.mystarbucks APPLE STORE APP ID ✓ bounty Critical
com.starbucks.mystarbucks.kr APPLE STORE APP ID ✓ bounty Critical
com.starbucks.sbuxsingapore APPLE STORE APP ID ✓ bounty Critical
com.starbucks.singapore GOOGLE PLAY APP ID ✓ bounty Critical
com.starbuckschina.mystarbucksmoments APPLE STORE APP ID ✓ bounty Critical
gift.starbucks.co.jp URL ✓ bounty Critical
Information Disclosures OTHER ✓ bounty Critical
login.starbucks.co.jp URL ✓ bounty Critical
openapi.starbucks.com URL ✓ bounty Critical
Other non domain specific items OTHER ✓ bounty Critical
secureui.starbucks.com URL ✓ bounty Critical
Subdomain Takeover (SDTO) OTHER ✓ bounty Critical
www.starbucks.ca URL ✓ bounty Critical
www.starbucks.co.jp URL ✓ bounty Critical
www.starbucks.co.kr URL ✓ bounty Critical
www.starbucks.co.uk URL ✓ bounty Critical
www.starbucks.com URL ✓ bounty Critical
www.starbucks.com.br URL ✓ bounty Critical
www.starbucks.com.cn URL ✓ bounty Critical
www.starbucks.com.sg URL ✓ bounty Critical
www.starbucks.de URL ✓ bounty Critical
www.starbucks.fr URL ✓ bounty Critical
www.starbucksreserve.com URL ✓ bounty Critical
apply.starbucks.com URL out None
athome.starbucks.com URL out None
careers.starbucks.com URL out None
customerservice.starbucks.com URL out None
ec.starbucks.com.cn URL out None
istarbucks.co.kr URL out None
lsstar.starbucks.com URL out None
Other assets OTHER submit only Critical
preview.starbucks.com URL out None
Teavana OTHER out None
www.teavana.com URL out None

HackerOne lists 47 scope entries; its public listing groups many assets under one label, so identical entries are shown once.