7-Eleven franchisee-document data incident

An unauthorized third party accessed 7-Eleven systems used to store franchisee documents on April 8, 2026. Franchise-application documents containing personal information were involved in the incident.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

An unauthorized third party accessed 7-Eleven systems used to store franchisee documents on April 8, 2026. [3]

Impact

Franchise-application documents containing personal information were involved in the incident. [1][2][3]

Documented data types include:

  • Social Security numbers — Social Security numbers reported by the Washington incident directory for the Washington notification population. [1][2][3]
  • Dates of birth — Full dates of birth in the Washington directory and dates of birth in the HIBP corpus. [1][2][3]
  • Names — Names in the consumer notice and HIBP corpus. [1][2][3]
  • Contact information — Postal addresses in the consumer notice; email addresses, phone numbers, and physical addresses in the HIBP corpus. [1][2][3]
  • Passport numbers — Passport numbers reported by the Washington incident directory for the Washington notification population. [1][2][3]

A cited record reports 1,940 individuals (Washington residents reported in the state incident directory; a jurisdictional subset, not an overall total; as of 2026-05-15). [1][2][3]

A cited record reports 185,256 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a person-level notification total; as of 2026-05-24). [1][2][3]

Timeline

  1. Documented event

    Date of unauthorized access in the consumer notice and incident date in the Washington directory; no duration is asserted.

    [1][3]
  2. Public disclosure

    Date on the 7-Eleven consumer notice.

    [3]
  3. Public disclosure

    Washington Attorney General report date.

    [1]
  4. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

7-Eleven offered affected recipients up to 24 months of no-cost IDX identity-theft protection and CyberScan monitoring. 7-Eleven said an unauthorized third party gained access to certain systems used to store franchisee documents. 7-Eleven said it initiated an investigation with a leading forensics firm to assess and remediate the incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]