7-Eleven data breach affects franchisee information
Unauthorized access to internal systems exposed sensitive documents, with limited regional impact confirmed.
7-Eleven has disclosed a data breach involving unauthorized access to internal systems used to store franchisee documents earlier this spring. The incident, identified on April 8, 2026, affected a limited number of individuals and did not disrupt the company’s operations, according to the retailer.
The breach involved personal information submitted during the franchise application process, including names and addresses. In some cases, more sensitive data such as Social Security numbers and driver’s license information was also compromised, based on filings in affected U.S. states.
Jim Kastle, Chief Information Security Officer at 7-Eleven, stated: “an unauthorized third party gained access to certain 7-Eleven systems used to store franchisee documents,” in a letter sent to impacted individuals on May 1.
According to regulatory filings, 50 individuals were affected across Massachusetts, Maine and Vermont, although it remains unclear whether additional cases occurred in other regions. The company has notified law enforcement and engaged third-party cybersecurity specialists to investigate the incident and strengthen its systems.
7-Eleven emphasized that there has been no operational disruption and that the breach was contained. As a precaution, the company is offering affected individuals up to 24 months of identity theft protection and monitoring services.