HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
7-Eleven, Inc.
bd_be76aaeac3e0c63c · schema v1 · pii pii-v1
Full breach record for 7-Eleven, Inc. →7-Eleven, Inc. notified Massachusetts residents of a security incident occurring on April 8, 2026, where an unauthorized third party accessed systems containing franchisee application documents. Affected data included names, addresses, and Social Security numbers. 7-Eleven engaged forensic investigators and provided 24 months of identity theft protection and credit monitoring via IDX.
Massachusetts clock✓ MA AG ≤30d23 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_5b9939babfe1fc87Leak Siteshinyhuntersfiled 2026-04-18(13d gap)Candidate
Regulatory filings (2) · sorted by filing gap
- bd_958948d4c00531daIndiana State AGfiled 2026-05-01Candidate
- bd_48dca4bfa65140deMaine State AGfiled 2026-05-15(14d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-790-7-eleven-inc/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 04eaa81f91102063698b0ffd2c1d6d2103b2404e83137d493fabbbdf1d2b03bc
Reporting entity
- Name
- 7-Eleven, Inc.norm: 7 eleven
- Domain
- 7-eleven.com
Victim entity
- Name
- 7-Eleven, Inc.norm: 7 eleven
- Domain
- 7-eleven.com
Incident
- Discovered
- Apr 8, 2026
- Materiality determined
- —
- Notification sent
- May 1, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 23 days(23 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.