7-Eleven confirmed that an unauthorized third party accessed systems used to store franchisee documents on April 8, leading to a breach involving personal information submitted during the franchise application process. The company began notifying affected individuals in May and said the total number impacted is still unknown, while ShinyHunters claimed it stole more than 600,000 records from a Salesforce environment containing corporate data and personally identifiable information.
After alleging that 7-Eleven refused to pay, ShinyHunters published a 9.4GB archive of documents on its leak site, escalating a broader campaign that has targeted Salesforce customers since mid-2025. The same extortion group was also linked to a separate breach at Colombian fintech Addi, where a leaked dataset reportedly exposed 34 million unique email addresses along with credit, identity, and socioeconomic data, underscoring the group’s continued focus on monetizing large stores of sensitive customer and business records.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
By 2026-05-26, reporting on 7-Eleven's breach said the incident exposed the personal information of about 185,300 individuals. The compromised data reportedly included names, dates of birth, email addresses, phone numbers, and physical addresses.
By 2026-05-18, 7-Eleven publicly confirmed a data breach involving unauthorized access to systems storing franchisee documents. Reporting tied the incident to ShinyHunters' claims of stealing over 600,000 Salesforce records containing personal and corporate information.
By 2026-05-18, reporting on the Addi incident said ShinyHunters had claimed responsibility and released a large dataset allegedly stolen from the company. The exposed data reportedly included 34 million unique email addresses and extensive financial and identity-related records.
On 2026-05-01, 7-Eleven sent breach notifications and filed disclosures in multiple U.S. states confirming that personal information was accessed in the April 8 incident. The company did not disclose the total number of affected individuals.
After 7-Eleven allegedly refused to pay, ShinyHunters published a 9.4GB archive of stolen 7-Eleven documents on its dark web leak site. The leak followed the group's earlier extortion demand tied to the claimed Salesforce data theft.
On 2026-04-17, ShinyHunters claimed it had stolen more than 600,000 records from 7-Eleven's Salesforce environment containing personal and internal corporate data. The group said it would publish the data if a ransom was not paid by 2026-04-21.
On 2026-04-08, an unauthorized third party accessed certain 7-Eleven systems used to store franchisee documents. The compromised files included information submitted during the franchise application process.
In March 2026, Colombian fintech company Addi detected unauthorized activity on its platform and notified customers that their personal information may have been compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
11 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcethecyberthrone.in
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcehaveibeenpwned.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.