Find notable cyber news and cases, enriched with sources, timelines, and signals.

7-Eleven hit by network compromise

Incident
First reported
Last updated
Happening score
H score 27
1 unique sources, 2 articles

Summary

Hide ▲

7-Eleven is a victim-focused breach incident in which an unauthorized third party accessed systems used to store franchisee documents on April 8, 2026, triggering an investigation and breach notifications. The event later escalated into data-theft extortion after ShinyHunters claimed responsibility, said it stole over 600,000 records from the company’s Salesforce environment, and leaked a 9.4GB archive after ransom demands were refused. Have I Been Pwned estimated the exposed data covered 185,300 people, including names, dates of birth, email addresses, phone numbers, and physical addresses.

Related Happenings

Charter Communications hit by network compromise linked to ShinyHunters

Incident
First: 26.05.2026 22:46 Last: 26.05.2026 22:46 Sources 1

About this happening: **Charter Communications** confirmed a **data breach** tied to **ShinyHunters** extortion, raising the risk of customer-data exposure and active follow-on pressure. The company sa...

7-Eleven franchisee-docs and Salesforce data leak

Data Leak
First: 18.05.2026 14:25 Last: 18.05.2026 14:25 Sources 1

How related: Less than a week after claiming the breach, ShinyHunters leaked a 9.4GB archive of documents on their dark web leak site after the company refused to pay a ransom to have the stolen data returned and destroyed.

About this happening: **7-Eleven** confirmed a **April 8, 2026** intrusion into systems used to store **franchisee documents**, and **ShinyHunters** later claimed the theft of **more than 600,000 Sales...

Latest development: 26.05.2026 10:01

Have I Been Pwned analyzed the leaked 7-Eleven data and estimated that the breach exposed personal information for 185,300 people, including names, dates of birth, unique email addresses, phone numbers, and physical addresses. The exposed archive was tied to ShinyHunters' extortion campaign against 7-Eleven and followed the group's leak-site posting after ransom demands were not met.

Aleksey Olegovich Volkov sentenced in Yanluowang ransomware case

Law Enforcement
First: 24.03.2026 15:06 Last: 24.03.2026 15:06 Sources 1

About this happening: The **Justice Department** said **Aleksey Olegovich Volkov** was **sentenced to 81 months** in prison for serving as an **initial access broker** in **Yanluowang ransomware** atta...

Aura customer data exposed after Aura breach

Data Leak
First: 19.03.2026 00:56 Last: 19.03.2026 00:56 Sources 1

About this happening: Aura confirmed a **data leak** that exposed nearly **900,000 customer records**, creating privacy and phishing risk for affected customers. The exposed set included **names**, **e...

Betterment customer data leak after January systems breach

Data Leak
First: 05.02.2026 13:16 Last: 05.02.2026 13:16 Sources 1

About this happening: **Betterment** suffered a **systems breach in January** that exposed personal information from **about 1.4 million accounts**. The stolen dataset included **email addresses, names...

Timeline

  1. 19.05.2026 17:16 1 articles · 8d ago

    Unauthorized access to 7-Eleven systems

    Initial Disclosure

    An unauthorized third party gained access to certain 7-Eleven systems used to store franchisee documents, and 7-Eleven said it immediately launched an investigation to assess the affected documents and notify impacted people.

    Show sources
  2. 19.05.2026 17:16 1 articles · 8d ago

    ShinyHunters claims responsibility

    Attribution Update

    ShinyHunters claimed responsibility for the 7-Eleven breach and said it had stolen over 600,000 records containing corporate data and personally identifiable information after breaching the company's Salesforce environment.

    Show sources
  3. 19.05.2026 17:16 3 articles · 8d ago

    7-Eleven sends breach notifications

    Victim Impact Update

    7-Eleven sent data breach notifications to affected individuals and filed notices in multiple U.S. states, saying attackers had accessed some systems and that the breach involved the personal information of an undisclosed number of individuals.

    Show sources