Another major cyberattack has been added to the growing list of data breaches affecting multinational retailers. Convenience store chain 7-Eleven has confirmed that cybercriminals gained access to its internal systems, resulting in the exposure of personal information of more than 183,000 people.

According to the notification service Have I Been Pwned, the attack is attributed to the notorious ShinyHunters, which has been linked to some of the world's largest data breaches in recent years. The attackers allegedly gained access to Salesforce and stole hundreds of thousands of files containing corporate documents and personally identifiable information.
Founded in 1927, 7-Eleven is now one of the world's largest convenience retail giants, with more than 86,000 stores in dozens of countries and millions of customers every day. The company also operates brands such as Speedway, Stripes and Laredo Taco Company, while its loyalty programs 7Rewards and Speedy Rewards have more than 100 million members.
See also: 7-Eleven data breach: ShinyHunters behind the attack?
What data was exposed in the 7-Eleven breach?
The company revealed that the breach was discovered on April 8, 2026, when unknown individuals gained access to systems used to store franchisee documents. While 7-Eleven did not provide an exact number of victims, Have I Been Pwned's analysis showed that approximately 185,300 people were affected.
The leaked data includes names, physical addresses, dates of birth, phone numbers and unique email addresses. Some files also contained additional personal information, increasing the risk of targeted fraud, phishing attacks and identity theft.
Cybersecurity experts warn that this kind of information is “gold” for cybercriminals. By combining emails, phone numbers and personal data, perpetrators can create highly convincing scam scenarios or resell the data to other criminal groups via dark web marketplaces.

ShinyHunters and attacks on Salesforce environments
The ShinyHunters group has emerged as one of the most active and dangerous cybercriminals globally. Recently, the group has systematically turned to attacks targeting cloud CRM platforms and Salesforce environments.
In the case of 7-Eleven, the perpetrators claimed to have stolen more than 600,000 files and then published approximately 9.4GB of data on their dark web leak site after the company refused to pay a ransom.
See also: NYC Health and Hospitals: Data breach affects 1.8 million people
This tactic is now common practice in modern ransomware and extortion attacks. Instead of limiting themselves to just encrypting systems, cybercriminals are increasingly focusing on data theft, using the threat of a public leak as leverage.
ShinyHunters has been linked to attacks on major organizations such as the European Commission, Vimeo, Cisco, Google, Rockstar Games, Match Group, and Medtronic. Analysts believe the group now operates as an organized cyber extortion network with international operations.
Why attacks on loyalty programs are considered particularly dangerous
Attacks on retail companies are becoming increasingly important due to the huge customer databases they manage. Loyalty programs are one of the most valuable targets for hackers, as they collect personal information, purchase history and contact details of millions of users.
In the case of 7-Eleven, the company’s 100 million-plus loyalty program members make it an extremely attractive target. Even if the breach was limited to specific corporate systems, cybercriminals gained valuable data that could be used in future attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Analysts point out that many businesses still treat CRM environments as “secondary” systems, without the same security rigor that is applied to banking or manufacturing infrastructures.
See also: ZARA: Data breach affects 197,000 customers

FBI warns: Paying ransom is not a solution
The FBI recently reiterated its recommendation to victims of ransomware and cybercrime not to pay ransom to attackers. As the agency points out, paying does not guarantee that data will be deleted or that the perpetrators will not attempt further extortion in the future.
In fact, many criminal groups continue to sell or leak data even after millions of dollars in ransom payments, making data extortion attacks one of the most profitable forms of cybercrime of the last decade.
The 7-Eleven case demonstrates that even the largest multinational retailers remain vulnerable to modern threats, especially when huge volumes of personal data are concentrated in cloud services and third-party platforms.
source: www.bleepingcomputer.com
