7-Eleven
Incident posture
Timeline
Summary
7-Eleven experienced a cyberattack in which hackers accessed an internal server storing franchise documents and exfiltrated personal data including names, dates of birth, addresses, phone numbers, email addresses, and potentially Social Security numbers and driver’s license details. The breach was attributed to the ShinyHunters group, which claimed to have taken over 600,000 Salesforce records, demanded a ransom, and later offered the data for sale on a hacker forum. While official notifications indicated limited impact with only a few residents identified, the stolen information exposed over 185,000 individuals according to breach monitoring services. The company began notifying affected parties and strengthening its security measures.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 8, 2026, 7-Eleven detected an intrusion into the systems used to store franchisee documents. The intrusion was later attributed to the hacker group ShinyHunters, which had been targeting Salesforce instances of major organizations since mid-2025. ShinyHunters claimed to have accessed more than 600,000 Salesforce records containing personal and corporate data from 7-Eleven and posted the claim on its leak website on April 17. The group demanded a ransom, threatening to leak the data unless payment was made by April 21, and later offered to sell the stolen information for $250,000 on a hacker forum.
According to Have I Been Pwned, the breach resulted in the theft of personal information for over 185,000 individuals, including full names, dates of birth, home addresses, phone numbers, and email addresses. Reports from the Attorneys General of Maine and Massachusetts indicated that the exposed data could also contain Social Security numbers and driver’s license details. 7-Eleven’s Chief Information Security Officer Jim Kastle confirmed that the attackers gained access to an internal server where franchise documents were stored. The company began sending security incident notices after the detection and submitted a notification to the Maine Attorney General’s Office stating that unspecified personal information had been compromised. Although the total number of affected individuals was not disclosed, 7-Eleven noted that only two Maine residents were identified as impacted, suggesting the personal information compromise may be limited.
The exposed information had been collected during franchise applications, and the breach was recorded in April 2026. In response, 7-Eleven stated it was taking measures to notify victims and to strengthen its security systems. ShinyHunters has been linked to other recent attacks on companies such as Instructure, Vimeo, Wynn Resorts, Vercel, and Medtronic. using tactics that include phishing, abuse of third‑party integrations, or misconfigurations rather than exploiting vulnerabilities in Salesforce products themselves.
Sources
Sources available to members: 2 sources.