7-Eleven
Incident posture
Timeline
Summary
7-Eleven experienced a breach when unauthorized actors accessed systems holding franchisee documents, with the extortion group ShinyHunters claiming responsibility and alleging the theft of over 600,000 Salesforce records. The compromised data, later published and indexed by Have I Been Pwned, exposed approximately 185,300 individuals’ names, email addresses, physical addresses, dates of birth, and phone numbers, with a smaller subset also having Social Security numbers and driver’s license information exposed.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 8, 2026, 7-Eleven detected unauthorized access to systems used for franchisee documents. The intrusion was later attributed to the extortion group ShinyHunters, which claimed responsibility on April 17, 2026. ShinyHunters asserted that it had stolen more than 600,000 Salesforce records from the company. The group placed the alleged data on its leak website in mid-April and demanded a ransom payment by April 21, 2026. When the ransom was not paid, ShinyHunters offered the data for sale on a Russian hacking forum and subsequently published a 9.4GB archive online. The leaked archive was later indexed by the breach notification service Have I Been Pwned.
Have I Been Pwned determined that the exposed dataset consisted of approximately 185,300 accounts, containing names, email addresses, physical addresses, dates of birth, and phone numbers. The service noted that the leaked information matched 7-Eleven’s own description of the incident and included additional fields for a small subset of individuals. Separate filings with state attorneys general provided further detail: the Maine Attorney General’s office recorded a statement from 7-Eleven’s chief information security officer Jim Kastle that the hackers accessed an internal server holding franchisee documents, while the Massachusetts Attorney General’s office indicated that the breach also exposed Social Security numbers and driver’s license numbers. In response to the discovery, 7-Eleven issued breach notices on May 1, 2026, and notified the relevant state authorities. The incident was described by Have I Been Pwned as a hack-and-extortion attack, with ShinyHunters stating that it would publish the data if its demands were not met.
Sources
Sources available to members: 3 sources.