ShinyHunters vs. 7-Eleven: 185,000 victims, 9.4GB leaked on the dark web

Here is what happened — and what it means for your organization.
In April 2026, 7-Eleven confirmed a significant data breach after the ShinyHunters extortion gang gained unauthorized access to its franchise application systems. The intrusion, which occurred on April 8, targeted internal platforms used to store franchisee documents — not the retail operations, but the corporate infrastructure behind them.
The data exposed included the personal information of over 185,000 current, former, and prospective franchisees:
Full names and home addresses Social Security numbers (SSNs) Driver's license information 600,000+ Salesforce CRM records
ShinyHunters issued a ransom demand with a hard deadline: April 21. 7-Eleven refused. The gang immediately published a 9.4GB archive on their dark web leak site — making the data available to any threat actor.
This is not just a breach. It is a pattern.
ShinyHunters has been systematically targeting Salesforce instances across major organizations since mid-2025. Their victim list already includes the European Commission, Cisco, Google, Vimeo, Zara, ADT, Medtronic, and Rockstar Games. 7-Eleven is the latest — not the last.
What makes this incident especially severe is the type of data compromised. Social Security numbers and driver's licenses cannot be rotated like passwords. Once exposed, they create a permanent attack surface — enabling identity theft, synthetic fraud, and targeted phishing for years.
Three takeaways for security teams
1. Peripheral systems carry full risk. Franchise portals, partner onboarding platforms, and document management systems store highly sensitive PII. They are often under-secured compared to core infrastructure. That gap is exactly what ShinyHunters exploited.
2. Salesforce is a high-value target. Large CRM deployments hold personal, financial, and corporate intelligence at scale. Access controls, session monitoring, and anomaly detection on these platforms must match the sensitivity of the data they hold.
3. Non-payment requires a response plan. Refusing to pay a ransom is the right call — it avoids funding criminal operations and rarely prevents publication anyway. But 7-Eleven's experience shows that when you decline, the leak is immediate. Your incident response plan must be built for that reality.
The 9.4GB is already out there. For 185,000 people, the exposure is permanent.
If your organization manages franchise data, partner records, or large Salesforce deployments — this is not a cautionary tale. It is a technical preview of what insufficient CRM security looks like in 2026.
Audit access. Monitor instances. Assume breach.