EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-7-eleven-shinyhunters-breach
041/430

File EL-0390HighResolvedData Breach / Extortion with Data Exfiltration

7-Eleven Data Breach

Also filed as ShinyHunters 7-Eleven Hack · 7-Eleven Customer Data Leak

The ShinyHunters extortion gang breached convenience store chain giant 7-Eleven, stealing the personal information of over 185,000 people.

  • #retail
  • #convenience-stores
  • #pii
  • #extortion
Notoriety7/10
Event
1 Apr 2026
Disclosed
26 May 2026
Target
7-Eleven
Actor
ShinyHunters
Scale
185K people
Status
Resolved

01Summary

In April 2026, ShinyHunters gained unauthorized access to 7-Eleven's systems and exfiltrated customer data. The stolen records were confirmed by Have I Been Pwned on May 24 with 185,300 affected accounts. 7-Eleven confirmed the breach in mid-May 2026, stating that customer PII including names, email addresses, and phone numbers were exposed.

02Background

7-Eleven operates over 70,000 stores across 17 countries, making it the world's largest convenience store chain.

03Technical analysis

The attack followed ShinyHunters' established methodology involving social engineering to compromise employee credentials for bulk data exfiltration.

Attack vector
Social engineering / Credential compromise
Attack method
Data exfiltration and extortion
Initial access
Social engineering (likely vishing)
Exfiltration
Bulk data extraction

04Threat actor

ShinyHunters is a prolific cybercriminal/extortion group.

Aliases

  • SH

Attribution sources

  • ShinyHunters leak site
  • BleepingComputer
  • Have I Been Pwned
  • 7-Eleven statements

05Victims and impact

Countries affected

  • United States

06Data exposed

Data types

  • PII
  • Names
  • Email addresses
  • Phone numbers

07Financial damage

Reputational damage and regulatory exposure.

08Timeline

  1. 2026-04-01Approximate date of breach.
  2. 2026-05-24Breach listed on HIBP.

09Reaction and fallout

Public reaction

Concern among customers about loyalty program data exposure.

10Significance and legacy

Significance

Part of ShinyHunters' massive 2026 multi-sector campaign.

11Disclosure and media

Authentication
7-Eleven confirmation and HIBP listing

Publishing organisations

  • BleepingComputer
  • Have I Been Pwned

12Related files

Related events

  • 2026-charter-communications-shinyhunters-breach

13Field notes

  1. 017-Eleven operates over 70,000 stores in 17 countries.

14Resolution

7-Eleven confirmed the breach and began notifying affected customers.

15Sources

Official documents

  • 7-Eleven data breach notification

References

  1. [1]BleepingComputer: 7-Eleven data breach coverage
  2. [2]Have I Been Pwned - 7-Eleven listing
Fact sheetEL-0390

Dates

Event
1 Apr 2026
Started
1 Apr 2026
Discovered
1 Apr 2026
Disclosed
26 May 2026
Ongoing
No

Target

Organisation
7-Eleven, Inc.
Type
Retail Company
Sector
Convenience Retail
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Financial gain through data extortion.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

People
185,300
Records
185,300
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Likely (standard for ShinyHunters)

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.