---
title: "7-Eleven franchisee-document data incident"
description: "Evidence-backed account of 7-Eleven franchisee-document data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/7-eleven-franchisee-document-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/7-eleven-franchisee-document-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/7-eleven-franchisee-document-data-incident-2026/stix.json"
---

# 7-Eleven franchisee-document data incident

An unauthorized third party accessed 7-Eleven systems used to store franchisee documents on April 8, 2026. Franchise-application documents containing personal information were involved in the incident.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An unauthorized third party accessed [7-Eleven](https://www.7-eleven.com/) systems used to store franchisee documents on April 8, 2026. [3](#source-3)

## Impact

Franchise-application documents containing personal information were involved in the incident. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Social Security numbers — Social Security numbers reported by the Washington incident directory for the Washington notification population. [1](#source-1) [2](#source-2) [3](#source-3)
- Dates of birth — Full dates of birth in the Washington directory and dates of birth in the HIBP corpus. [1](#source-1) [2](#source-2) [3](#source-3)
- Names — Names in the consumer notice and HIBP corpus. [1](#source-1) [2](#source-2) [3](#source-3)
- Contact information — Postal addresses in the consumer notice; email addresses, phone numbers, and physical addresses in the HIBP corpus. [1](#source-1) [2](#source-2) [3](#source-3)
- Passport numbers — Passport numbers reported by the Washington incident directory for the Washington notification population. [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 1,940 individuals (Washington residents reported in the state incident directory; a jurisdictional subset, not an overall total; as of 2026-05-15). [1](#source-1) [2](#source-2) [3](#source-3)

A cited record reports 185,256 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not a person-level notification total; as of 2026-05-24). [1](#source-1) [2](#source-2) [3](#source-3)

## Timeline

### April 8, 2026 — Documented event

Date of unauthorized access in the consumer notice and incident date in the Washington directory; no duration is asserted. [1](#source-1) [3](#source-3)

### May 1, 2026 — Public disclosure

Date on the 7-Eleven consumer notice. [3](#source-3)

### May 15, 2026 — Public disclosure

Washington Attorney General report date. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

7-Eleven offered affected recipients up to 24 months of no-cost IDX identity-theft protection and CyberScan monitoring. 7-Eleven said an unauthorized third party gained access to certain systems used to store franchisee documents. 7-Eleven said it initiated an investigation with a leading forensics firm to assess and remediate the incident. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/7-eleven-franchisee-document-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Breach Notifications Directory — 2026 entries

regulatory · Washington State Office of the Attorney General

<https://www.atg.wa.gov/data-breach-notifications?page=1>

<a id="source-2"></a>

### 7-Eleven breach record

advisory · Have I Been Pwned · May 24, 2026

<https://haveibeenpwned.com/api/v3/breach/7-Eleven>

<a id="source-3"></a>

### 7-Eleven notice of security incident

regulatory · 7-Eleven, Inc. via Washington State Office of the Attorney General · May 1, 2026

<https://agportal-s3bucket.s3.amazonaws.com/databreach/BreachA40850.pdf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Individual Count · 100% confidence · current**  
   7-Eleven franchise-application data exposure: 1,940 individual
2. **Resulted In · 100% confidence · current**  
   7-Eleven May 2026 security-incident notification: 7-Eleven offered affected recipients up to 24 months of no-cost IDX identity-theft protection and CyberScan monitoring.
3. **Resulted In · 100% confidence · current**  
   April 2026 7-Eleven franchisee-systems incident: 7-Eleven May 2026 security-incident notification
4. **Resulted In · 100% confidence · current**  
   April 2026 7-Eleven franchisee-systems incident: 7-Eleven said an unauthorized third party gained access to certain systems used to store franchisee documents.
5. **Exposed Data Category · 100% confidence · current**  
   7-Eleven franchise-application data exposure: Social Security numbers
6. **Exposed Data Category · 100% confidence · current**  
   7-Eleven franchise-application data exposure: Dates of birth
7. **Affected Organization · 100% confidence · current**  
   7-Eleven franchise-application data exposure: 7-Eleven, Inc.
8. **Resulted In · 100% confidence · current**  
   April 2026 7-Eleven franchisee-systems incident: 7-Eleven said it initiated an investigation with a leading forensics firm to assess and remediate the incident.
9. **Affected Organization · 100% confidence · current**  
   April 2026 7-Eleven franchisee-systems incident: 7-Eleven, Inc.
10. **Exposed Record Count · 100% confidence · current**  
   7-Eleven franchise-application data exposure: 185,256 record
11. **Exposed Data Category · 100% confidence · current**  
   7-Eleven franchise-application data exposure: Names
12. **Disclosed At · 100% confidence · current**  
   7-Eleven May 2026 security-incident notification: 2026-05-15
13. **Disclosed At · 100% confidence · current**  
   7-Eleven May 2026 security-incident notification: 2026-05-01
14. **Resulted In · 100% confidence · current**  
   April 2026 7-Eleven franchisee-systems incident: 7-Eleven franchise-application data exposure
15. **Occurred At · 100% confidence · current**  
   April 2026 7-Eleven franchisee-systems incident: 2026-04-08
16. **Exposed Data Category · 100% confidence · current**  
   7-Eleven franchise-application data exposure: Contact information
17. **Exposed Data Category · 100% confidence · current**  
   7-Eleven franchise-application data exposure: Passport numbers

</details>
