Advertisement

7-Eleven Data breach exposes personal information of over 185,000 people

A data breach at 7-Eleven reportedly exposed the personal information of more than 185,000 people in a hacking and extortion attack linked to ShinyHunters

Advertisement
FP Tech Desk|May 26, 2026, 20:41:27 IST

Have I Been Pwned, a data breach notification service, said that a breach involving convenience store chain 7-Eleven affected more than 185,000 people and exposed sensitive personal information, including names, dates of birth and physical addresses. The breach, which was reported in April, also leaked phone numbers and email addresses.

Advertisement

Have I Been Pwned, which collects databases of known breaches and alerts affected individuals when their data has been compromised, said in a new listing that 7-Eleven was the victim of a hacking and extortion attack. A notorious cybercrime group known as ShinyHunters claimed responsibility for the breach and allegedly warned that it would release the stolen data if its demands were not met.

techMore from Tech

7-Eleven Chief Information Officer Jim Kastle said the hackers gained access to an internal server containing franchisee documents. A filing with the Massachusetts Attorney General’s office stated that the breach also exposed Social Security numbers and driver’s licence details.

The company said the infiltration was carried out through a poisoned Visual Studio Code extension. Cybercrime group Team PCP claimed responsibility for the attack and is reportedly marketing GitHub’s private source code and internal data on dark web forums, demanding a minimum payment of $50,000 from potential buyers.

Advertisement

The stolen data allegedly includes core components of GitHub’s internal architecture, such as code related to GitHub Actions, agentic workflows, Copilot internal projects and Rails controllers used to manage pull requests.

Following the detection of the breach, GitHub said it isolated the compromised employee endpoint, removed the malicious extension from the VS Code Marketplace and carried out an aggressive overnight secret rotation to invalidate stolen API keys and credentials.

The incident follows a series of 2026 supply-chain attacks linked to Team PCP and its self-propagating “Mini Sahi-Hulud” worm, which had previously targeted developer tools including the TanStack Router ecosystem and the Trivy vulnerability scanner.

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:May 26, 2026, 19:53:50 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next