惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
The GitHub Blog
The GitHub Blog
博客园 - Franky
酷 壳 – CoolShell
酷 壳 – CoolShell
Recent Announcements
Recent Announcements
量子位
aimingoo的专栏
aimingoo的专栏
大猫的无限游戏
大猫的无限游戏
博客园 - 叶小钗
Microsoft Azure Blog
Microsoft Azure Blog
Martin Fowler
Martin Fowler
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
T
Tailwind CSS Blog
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
G
Google Developers Blog
M
MIT News - Artificial intelligence

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY Frontier AI models reap rapid discovery of security vulnerabilities
7-Eleven hit by data breach
Brett Dworski · 2026-05-20 · via Cybersecurity Dive - Latest News

Dive Brief:

  • Hackers breached 7-Eleven earlier this spring in an attack that exposed some franchisee information, a company spokesperson confirmed to C-Store Dive on Tuesday.
  • The retailer learned on April 8 that an unauthorized third party gained access to certain 7-Eleven systems used to store franchisee documents, Jim Kastle, 7-Eleven’s chief information security officer, said in a letter sent to impacted individuals on May 1. Those documents included personal information provided to 7-Eleven during the franchise application process.
  • About 50 people in Massachusetts, Maine and Vermont were impacted by the incident, according to data breach filings presented to those states last week. It’s not clear if other individuals across the country were also affected.

Dive Insight:

7-Eleven’s spokesperson said that the convenience retailer “immediately launched an investigation and began taking steps to contain the incident” upon discovering it. The company has notified law enforcement and retained third-party cybersecurity experts, and hasn’t experienced any disruption to operations, the spokesperson emphasized.

“We identified a limited number of current, former, and prospective Franchisees whose data was involved in this incident, and we are in the process of contacting those affected individuals,” 7-Eleven’s spokesperson said. “We have no reason to believe that customer data was affected.” 

In the May 1 letter, Kastle said the franchisee information obtained in the breach included names and addresses, among other elements. The Vermont filing noted that the breach included Social Security numbers, while the Massachusetts site noted Social Security numbers and drivers license data were compromised.

Kastle added that 7-Eleven has arranged for impacted individuals to enroll in identity theft protection services with theft protection agency IDX for up to 24 months.

The breach impacted 47 people in Massachusetts, 2 in Maine and one in Vermont, according to each state’s filing.

“We also wanted to apologize for any inconvenience this may cause you,” Kastle said in the letter.

7-Eleven’s confirmation of the breach comes several weeks after reports surfaced that cyber gang ShinyHunters claimed responsibility for the attack, which it said compromised more than 600,000 Salesforce records from the convenience retailer. 7-Eleven’s spokesperson did not respond by press time when asked about this information. In April, a spokesperson from Salesforce declined to comment when asked to confirm the reports.

7-Eleven isn’t the only major convenience retailer to have recently suffered a cyber attack. Gas Express LLC, a Circle K franchisee that has about 200 locations, reported a breach in January that exposed employees’ names, social security numbers and driver’s license numbers. About three weeks later, Gas Express was sued in Georgia for failing to protect its employees during the breach, as well as for failing to notify impacted employees of the breach when it happened. That lawsuit was settled earlier this month.