Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Franchise-application documents containing personal information were involved in the incident. [1][2][3]
Documented data types include:
- Social Security numbers — Social Security numbers reported by the Washington incident directory for the Washington notification population. [1][2][3]
- Dates of birth — Full dates of birth in the Washington directory and dates of birth in the HIBP corpus. [1][2][3]
- Names — Names in the consumer notice and HIBP corpus. [1][2][3]
- Contact information — Postal addresses in the consumer notice; email addresses, phone numbers, and physical addresses in the HIBP corpus. [1][2][3]
- Passport numbers — Passport numbers reported by the Washington incident directory for the Washington notification population. [1][2][3]
A cited record reports 1,940 individuals (Washington residents reported in the state incident directory; a jurisdictional subset, not an overall total; as of 2026-05-15). [1][2][3]
A cited record reports 185,256 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a person-level notification total; as of 2026-05-24). [1][2][3]
Timeline
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
7-Eleven offered affected recipients up to 24 months of no-cost IDX identity-theft protection and CyberScan monitoring. 7-Eleven said an unauthorized third party gained access to certain systems used to store franchisee documents. 7-Eleven said it initiated an investigation with a leading forensics firm to assess and remediate the incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]
