Skip to main content
Back to overview
Medium

7-Eleven data breach exposes franchisee applicant data

Cybersecurity Week in Review: May 26, 2026 – June 1, 2026 Cyberattacks, data breaches, zero-days, and global responses—discover the biggest cybersecurity headlines of this week.

Key points

  • Data breach by ShinyHunters extortion group.
  • Affected 7-Eleven, a convenience store chain.
  • Exposed data of approximately 185,000 franchisee applicants.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Jun 2, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking, Error activity

Watch phishing, executive impersonation and account-takeover exposure.

  • Source type: possible insider or internal misuse

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

7 ElevenData DisclosureElevenCybersecurity WeekReviewCyberattacksTuesdayMondayCharter CommunicationsShinyHunters

Quick context

Questions about this signal

What happened in this signal?

Cybersecurity Week in Review: May 26, 2026 – June 1, 2026 Cyberattacks, data breaches, zero-days, and global responses—discover the biggest cybersecurity headlines of this week. This week’s cybersecurity landscape was marked by a surge in high-impact data breaches, aggressive exploitation of critical vulnerabilities, and a series of government advisories aimed at bolstering defenses across sectors. The period from Tuesday, May 26, through Monday, June 1, 2026, saw threat actors targeting major enterprises, public infrastructure, and widely used software platforms, underscoring the relentless pace and sophistication of modern cyber threats. Charter Communications: Massive Data Leak Impacts Millions Charter Communications, one of the largest US telecommunications providers, suffered a significant data breach after the ShinyHunters group leaked over 13 million customer records on the dark web. Exposed data included full names, email addresses (primarily workplace domains), company and home addresses, and details from nearly 10 million customer support tickets. Additionally, records on approximately 27,000 employees—including work emails and job titles—were compromised. The breach is believed to have originated from a vishing attack that compromised an employee’s Microsoft Entra account, allowing attackers to pivot into the company’s Salesforce environment. Charter has denied that sensitive personal or proprietary network information was exfiltrated, but the leaked data poses substantial risks for social engineering and spearphishing attacks targeting both customers and staff 1 ​ 2 . Attack vector: Vishing, credential compromise, Salesforce exploitation Response: Charter refused ransom demands, leading to public data release; authorities notified Trump Mobile: Pre-Order Customer Data Exposed Trump Mobile confirmed a data breach affecting over 27,000 customers who pre-ordered the T1 smartphone. The incident was traced to a security flaw in the company’s website pre-order form, which exposed names, addresses, email addresses, order identifiers, and mobile phone numbers. No payment or highly sensitive financial data was reported as compromised. The company has implemented additional safeguards and is evaluating notification obligations 3 . Attack vector: Web application vulnerability Data exposed: Personal contact details of pre-order customers Response: Security enhancements, customer vigilance advisories 7-Eleven: Franchisee and Customer Data Breach 7-Eleven disclosed a breach that exposed the personal information of approximately 185,000 individuals, including franchisee application records. The breach increased the risk of identity theft and phishing attacks across its North American franchise network 4 . Attack vector: Internal system compromise Data exposed: Names, addresses, sensitive franchisee data LA Metro: State-Sponsored Attack Disrupts Public Transit A disruptive cyberattack targeting the Los Angeles Metro system was attributed to Iranian state-sponsored hackers. The incident highlights the ongoing threat posed by nation-state actors to critical infrastructure in the US 5 . Impact: Service disruption, heightened sectoral alert Canvas (Instructure): Ransomware Attack Disrupts Education Sector Instructure, the parent company of the Canvas learning platform, reached an agreement with the ShinyHunters group after a ransomware attack threatened to leak data tied to nearly 275 million users across 9,000 educational institutions. The attackers claimed to have exfiltrated over 3.65 TB of data, including student records, email addresses, and private communications. The incident caused widespread disruption during a critical academic period and underscored the dilemma organizations face when negotiating with cybercriminals 6 . Attack vector: Ransomware, data exfiltration

When was this signal reported?

Shadow Tier lists Jun 2, 2026 as the signal date.

Which organization is connected to this signal?

7 Eleven is the organization connected to this public signal.

Explore 7 Eleven
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence