7-Eleven data breach exposes personal information of 185,000 people
7-Eleven says attackers accessed systems storing franchisee documents in April. HIBP says leaked data exposed names, birth dates, emails, phone numbers, and addresses.
Intelligence analysis by GPT-5.4 Mini

7-Eleven notified customers after a breach that began on April 8, 2026. Have I Been Pwned says the leaked material exposed data for 185,300 people, while ShinyHunters claimed the theft and leak.
7-Eleven found out that someone broke into some of its computer systems. That is like a thief sneaking into a back office and copying files that should have stayed private.
A security group that tracks leaks says the stolen files may include names, birthdays, email addresses, phone numbers, and home addresses for about 185,000 people. Those details can help scammers pretend to be real people.
The story matters because when personal information gets out, it can be used later for tricks and fraud. It is like leaving a house key with a label that also shows the home address.
Analysis
What happened
7-Eleven told affected customers that an unauthorized third party gained access to certain systems on April 8, 2026. The company said those systems were used to store franchisee documents, but it did not publicly identify the attackers or explain the full intrusion path.
What data was exposed
According to Have I Been Pwned, the material leaked by ShinyHunters covered 185,300 people. The exposed fields included names, dates of birth, unique email addresses, phone numbers, and physical addresses. HIBP also said a small number of records contained additional fields.
Who claimed responsibility
ShinyHunters said it stole more than 600,000 records from 7-Eleven's Salesforce environment and later posted a 9.4GB archive on its leak site after the company did not pay. 7-Eleven did not confirm the group's claims to BleepingComputer, so the public record here is a mix of company notice, victim response, and third-party analysis.
Broader context
The article frames this as part of a longer campaign by ShinyHunters against Salesforce customers. It also notes that 7-Eleven Denmark suffered a ransomware attack in 2022, and that the FBI recently warned victims not to pay extortion demands because stolen data can still be reused or resold.
Key points
- 7-Eleven says an unauthorized party accessed systems used to store franchisee documents on April 8, 2026.
- Have I Been Pwned says the breach exposed data for 185,300 people.
- The exposed data included names, dates of birth, email addresses, phone numbers, and physical addresses.
- ShinyHunters claimed the theft and said it had breached 7-Eleven's Salesforce environment.
- The article says 7-Eleven did not confirm ShinyHunters' claims to BleepingComputer.



