Skip to main content

Company intelligence

7 Eleven cybersecurity incidents and threat signals

7-eleven.com

7 Eleven logo

This company page brings together public reporting currently associated with 7 Eleven. It reflects signals published by Shadow Tier and should not be read as a complete incident history.

3

Published signals

currently linked to this company

0

Last 28 days

recent published signals

2

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 22, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to 7 Eleven. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving 7 Eleven

7 Eleven logoRansomware
Medium

7-Eleven data breach exposes franchisee applicant data

Cybersecurity Week in Review: May 26, 2026 – June 1, 2026 Cyberattacks, data breaches, zero-days, and global responses—discover the biggest cybersecurity headlines of this week. This week’s cybersecurity landscape was marked by a surge in high-impact data breaches, aggressive exploitation of critical vulnerabilities, and a series of government advisories aimed at bolstering defenses across sectors. The period from Tuesday, May 26, through Monday, June 1, 2026, saw threat actors targeting major enterprises, public infrastructure, and widely used software platforms, underscoring the relentless pace and sophistication of modern cyber threats. Charter Communications: Massive Data Leak Impacts Millions Charter Communications, one of the largest US telecommunications providers, suffered a significant data breach after the ShinyHunters group leaked over 13 million customer records on the dark web. Exposed data included full names, email addresses (primarily workplace domains), company and home addresses, and details from nearly 10 million customer support tickets. Additionally, records on approximately 27,000 employees—including work emails and job titles—were compromised. The breach is believed to have originated from a vishing attack that compromised an employee’s Microsoft Entra account, allowing attackers to pivot into the company’s Salesforce environment. Charter has denied that sensitive personal or proprietary network information was exfiltrated, but the leaked data poses substantial risks for social engineering and spearphishing attacks targeting both customers and staff 1 ​ 2 . Attack vector: Vishing, credential compromise, Salesforce exploitation Response: Charter refused ransom demands, leading to public data release; authorities notified Trump Mobile: Pre-Order Customer Data Exposed Trump Mobile confirmed a data breach affecting over 27,000 customers who pre-ordered the T1 smartphone. The incident was traced to a security flaw in the company’s website pre-order form, which exposed names, addresses, email addresses, order identifiers, and mobile phone numbers. No payment or highly sensitive financial data was reported as compromised. The company has implemented additional safeguards and is evaluating notification obligations 3 . Attack vector: Web application vulnerability Data exposed: Personal contact details of pre-order customers Response: Security enhancements, customer vigilance advisories 7-Eleven: Franchisee and Customer Data Breach 7-Eleven disclosed a breach that exposed the personal information of approximately 185,000 individuals, including franchisee application records. The breach increased the risk of identity theft and phishing attacks across its North American franchise network 4 . Attack vector: Internal system compromise Data exposed: Names, addresses, sensitive franchisee data LA Metro: State-Sponsored Attack Disrupts Public Transit A disruptive cyberattack targeting the Los Angeles Metro system was attributed to Iranian state-sponsored hackers. The incident highlights the ongoing threat posed by nation-state actors to critical infrastructure in the US 5 . Impact: Service disruption, heightened sectoral alert Canvas (Instructure): Ransomware Attack Disrupts Education Sector Instructure, the parent company of the Canvas learning platform, reached an agreement with the ShinyHunters group after a ransomware attack threatened to leak data tied to nearly 275 million users across 9,000 educational institutions. The attackers claimed to have exfiltrated over 3.65 TB of data, including student records, email addresses, and private communications. The incident caused widespread disruption during a critical academic period and underscored the dilemma organizations face when negotiating with cybercriminals 6 . Attack vector: Ransomware, data exfiltration

7 Eleven
7 Eleven logoUse of stolen credentials or exploit
High

7-Eleven Sends Breach Notices After ShinyHunters Leak Threat

7-Eleven sent breach notices on May 1, 2026, following unauthorized access to systems used for franchisee documents, detected on April 8, 2026. The ShinyHunters group claimed responsibility on April 17, 2026, alleging the theft of over 600,000 Salesforce records and later leaking a 9.4GB archive after ransom negotiations failed. Have I Been Pwned listed 185.3 thousand exposed accounts, including names, email addresses, physical addresses, dates of birth, and phone numbers. 7-Eleven stated the breach was limited to certain franchisee-document systems.

7 Eleven
7 Eleven logoUse of stolen credentials or exploit
Medium

7-Eleven Data Breach Exposes Personal Information of 185,000 People

On April 8, 2026, convenience store giant 7-Eleven detected unauthorized access to systems used for franchisee documents. The ShinyHunters extortion gang later claimed responsibility, alleging theft of over 600,000 Salesforce records containing corporate data and personally identifiable information. Analysis of the leaked data by Have I Been Pwned confirmed that the breach exposed the personal information of approximately 185,300 individuals, including names, dates of birth, unique email addresses, phone numbers, and physical addresses.

7 Eleven

FAQ

Questions about 7 Eleven cybersecurity reporting

What does the 7 Eleven page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to 7 Eleven.

Does every mention of 7 Eleven appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.