7-Eleven Data Breach: Did You Apply for a Franchise? Your SSN May Have Been Stolen

ShinyHunters published 9.4GB of stolen 7-Eleven franchise application data on May 24. If you ever applied to open a franchise, your SSN and driver's license may be exposed.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

You handed over your Social Security number, driver's license, and home address to pursue a business opportunity with 7-Eleven. Now, that information may be in the hands of cybercriminals.[1]

The convenience store giant has confirmed a data breach affecting more than 185,000 franchise applicants after hackers linked to the ShinyHunters extortion group stole and published sensitive application records.

Exposed information includes Social Security numbers, driver's license details, dates of birth, and contact information.[2]

7-Eleven is offering 24 months of free identity monitoring, but the enrollment deadline is August 1, 2026. Here's what happened, what it means, and what steps to take.

In this article
What happened in the 7-Eleven data breach
What this means for franchise applicants
What to do right now after the 7-Eleven data breach
Bottom line

What happened in the 7-Eleven data breach

According to notices filed with state attorneys general and reporting from TechCrunch and BleepingComputer, 7-Eleven discovered unauthorized access to systems that store franchise application documents on April 8.

The company later determined that the exposed files contained information submitted by franchise applicants, including names, home addresses, phone numbers, email addresses, dates of birth, Social Security numbers, and driver's license information. More than 185,000 people have been notified.

But this recent ShinyHunters data breach is part of a broader campaign. 

ShinyHunters has been systematically targeting organizations' Salesforce systems since late 2025, exploiting misconfigured guest user permissions to steal records at scale. The group demanded a $250,000 ransom. When 7-Eleven declined to pay, ShinyHunters published a 9.4GB archive of stolen files online on May 24.

ShinyHunters is one of the most prolific criminal extortion groups operating today. The group has been linked to major breaches, including a recent attack on student data affecting thousands of schools, the Ticketmaster breach exposing 560 million customers, and an AT&T breach affecting more than 110 million accounts. Their method is consistent: steal data, demand ransom, publish if unpaid.

What this means for franchise applicants

Unlike many retail breaches that expose login credentials or payment information, franchise application data contains enough information to verify someone's identity across financial institutions, government agencies, and credit providers.

A Social Security number, government-issued ID, and home address can be used to open fraudulent accounts, apply for loans, file false tax returns, or create synthetic identities. Fraud isn't always immediate. Victims frequently don't discover misuse until months later, when damage is already done.

The long-term nature of the risk is another concern. While passwords can be changed and credit cards replaced, Social Security numbers are one-and-done.

The 7-Eleven data breach follows the same extortion model as the Krispy Kreme ransomware attack. Professional criminal groups specifically target business application data, not opportunistic hackers.

And the risk isn't theoretical. According to an identity theft survey by All About Cookies, data breaches are the leading cause of identity theft. Nearly two in five identity theft victims (38%) said a data breach was how criminals accessed their information in the first place. And the financial toll is real: identity theft victims spend an average of $3,312.66 resolving fraud, and restoring credit records can take months.

4.8
Editorial Rating
Get Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

What to do right now after the 7-Eleven data breach

If you applied for a 7-Eleven franchise at any point, take these steps now.

1. Check if you're affected. Go to Have I Been Pwned and enter the email address you used in your franchise application. The breach has been indexed there. You may also receive a mailed notification letter directly from 7-Eleven.

2. Enroll in free IDX monitoring. 7-Eleven is offering 24 months of free identity monitoring through IDX. Use the enrollment code in your notification letter or call 1-833-788-9712 (Mon–Fri, 9 am–9 pm ET).

3. Place a credit freeze at all three bureaus. Contact Equifax, Experian, and TransUnion individually to freeze your credit. It's free, takes a few minutes, and prevents anyone from opening new accounts in your name until you lift it.

4. Monitor for tax and financial fraud. SSN exposure creates risk beyond credit accounts. Watch for IRS notices about duplicate filings, unfamiliar tax documents, or new accounts you didn't open. Consider placing a fraud alert with the IRS as well.

5. Sign up for identity theft protection. A dedicated identity theft protection service provides ongoing dark web monitoring, real-time alerts, and identity restoration support if fraud does occur.

Learn more about identity theft prevention.

6. Use a data removal service. An automated data removal service submits opt-out requests to data broker databases on your behalf, reducing how many places your personal information is available to begin with.

Learn more about data broker removal or get started with a free exposure scan.

Bottom line

185,000 people's SSNs are now in criminal hands. That doesn't change. Your SSN doesn't expire, and neither does this risk. 7-Eleven is offering 24 months of free identity monitoring — more than most breach victims ever receive — but enrollment closes August 1.

Freeze your credit, enroll before the deadline, and stay alert for signs of fraud.

4.8
Editorial Rating
Get Deal
On Aura Identity Theft's website
2026 Editors’ Choice
Best Overall Identity Theft Protection Service
Identity Protection
Aura Identity Theft
PROMOTION: Save Up to 68%
  • ID theft protection that monitors your SSN, bank accounts, credit cards, and brokerage and retirement accounts for suspicious activity
  • Every plan includes the full feature set, so no additional cost to unlock monitoring, insurance, or restoration
  • Bundles data removal with identity theft protection, antivirus, VPN, and a password manager in one subscription

Citations

[1] NOTICE OF SECURITY INCIDENT

[2] 2026 Data Breach Notification Report