Cyber Incident Victim: 7-Eleven
Timeline
Summary
The convenience store chain 7‑Eleven experienced a breach when attackers accessed an internal server containing franchisee documents. The ShinyHunters extortion group claimed to have stolen 600,000 Salesforce records, demanded a ransom, and later published the data online. HaveIBeenPwned added the leaked information, which includes names, addresses, email addresses, dates of birth and phone numbers for about 185,300 individuals, with some records also containing Social Security numbers and driver’s license details according to state filings. The compromised data has been made available on hacking forums and the breach notification service.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On April 8, 2026, 7-Eleven detected unauthorized access to systems used for franchisee documents. The company later sent breach notices on May 1, 2026, after confirming the intrusion. On April 17, 2026, the extortion group ShinyHunters claimed responsibility for the breach and alleged that it had stolen more than 600,000 Salesforce records. After ransom talks failed, ShinyHunters leaked a 9.4‑gigabyte archive of the purported data.

Have I Been Pwned subsequently listed 185,300 exposed accounts, noting that the compromised information included names, email addresses, physical addresses, dates of birth and phone numbers. The breach notification filed with the Maine Attorney General’s Office stated that the incident occurred on April 8 and involved franchise‑document systems, while a separate filing with the Massachusetts Attorney General indicated that Social Security numbers and driver’s license details were also part of the exposed dataset for a small subset of individuals. ShinyHunters had previously listed 7‑Eleven on its leak website in mid‑April, claiming possession of 600,000 Salesforce records and demanding a ransom payment by April 21. When the ransom was not paid, the group offered the data for sale on a Russian hacking forum and later published the information online, which was then ingested by Have I Been Pwned for analysis.
According to Have I Been Pwned, the leaked information aligns with 7‑Eleven’s own statement and affects roughly 185,300 individuals, with additional data fields compromised for a small subset. The service described the incident as a hack‑and‑extortion attack, noting that ShinyHunters declared they would publish the data if payment was not received. Prior to the 7‑Eleven event, a February alert from Mandiant had warned of escalating ShinyHunters‑branded activity, and the group later claimed responsibility for attacks against Instructure, Vimeo, Wynn Resorts, Vercel and Medtronic. Related incidents cited by security observers include breaches at Radiology Associates of Richmond, DocketWise and American Lending Center.
