01Summary
In April 2026, ShinyHunters gained unauthorized access to 7-Eleven's systems and exfiltrated customer data. The stolen records were confirmed by Have I Been Pwned on May 24 with 185,300 affected accounts. 7-Eleven confirmed the breach in mid-May 2026, stating that customer PII including names, email addresses, and phone numbers were exposed.
02Background
7-Eleven operates over 70,000 stores across 17 countries, making it the world's largest convenience store chain.
03Technical analysis
The attack followed ShinyHunters' established methodology involving social engineering to compromise employee credentials for bulk data exfiltration.
- Attack vector
- Social engineering / Credential compromise
- Attack method
- Data exfiltration and extortion
- Initial access
- Social engineering (likely vishing)
- Exfiltration
- Bulk data extraction
04Threat actor
ShinyHunters is a prolific cybercriminal/extortion group.
Aliases
- SH
Attribution sources
- ShinyHunters leak site
- BleepingComputer
- Have I Been Pwned
- 7-Eleven statements
05Victims and impact
Countries affected
- United States
06Data exposed
Data types
- PII
- Names
- Email addresses
- Phone numbers
07Financial damage
Reputational damage and regulatory exposure.
08Timeline
- 2026-04-01Approximate date of breach.
- 2026-05-24Breach listed on HIBP.
09Reaction and fallout
Public reaction
Concern among customers about loyalty program data exposure.
10Significance and legacy
Significance
Part of ShinyHunters' massive 2026 multi-sector campaign.
11Disclosure and media
- Authentication
- 7-Eleven confirmation and HIBP listing
Publishing organisations
- BleepingComputer
- Have I Been Pwned
13Field notes
- 017-Eleven operates over 70,000 stores in 17 countries.
14Resolution
7-Eleven confirmed the breach and began notifying affected customers.
15Sources
Official documents
- 7-Eleven data breach notification
References
- [1]BleepingComputer: 7-Eleven data breach coverage
- [2]Have I Been Pwned - 7-Eleven listing









