🏳️‍⚧️ trans rights are human rights 🏳️‍⚧️
Theme

7-Eleven Left 600,000 People’s Social Security Numbers Unencrypted. Hackers Took Them.

7-Eleven Left 600,000 People’s Social Security Numbers Unencrypted. Hackers Took Them.

TL;DR

  • A class action filed May 29, 2026 in federal court in Dallas alleges 7-Eleven, Inc. failed to protect the personal data of over 600,000 people whose records were stolen in an April 2026 cyberattack.
  • The stolen data reportedly included names, Social Security numbers, dates of birth, addresses, phone numbers, email addresses, and driver’s license numbers. The complaint alleges none of it was encrypted or redacted.
  • The extortion group ShinyHunters claimed responsibility on April 17, 2026, and made the 600,000 records available for download on its dark web site after 7-Eleven allegedly refused to pay.
  • The complaint alleges 7-Eleven ignored FBI, FTC, CISA, and Microsoft security guidance, let security certificates lapse, and kept sensitive data it no longer needed.
  • The lawsuit brings claims for negligence, breach of implied contract, and unjust enrichment, seeking damages, lifetime credit monitoring, and forced security overhauls.
ShinyHunters posted a message claiming the company “failed to reach an agreement with us despite our incredible patience” and flatly stated: “They don’t care.”

The Non-Financial Ledger

The most permanent thing about you was handed to strangers. A Social Security number cannot be canceled like a credit card or reissued like a password. According to the complaint, the government does not normally replace one, and even a new number gets quickly linked back to the old, so the bad information follows you anyway. That means the people caught in this breach carry a risk that does not expire. It follows them for the rest of their lives.

The named plaintiff describes herself as someone who was always careful. She stored sensitive documents in a secure place, chose unique passwords, and never knowingly sent unencrypted information over the internet. None of that mattered. The company she trusted with her data allegedly left it sitting unencrypted on its systems, and now she spends her hours monitoring accounts, changing passwords, and watching her credit for fraud that may take years to surface.

The complaint documents the quieter cost too: emotional distress, anxiety, loss of control over her most intimate information, and the exhausting knowledge that she must stay vigilant forever. This is the harm that never shows up on a balance sheet. It is the feeling of being permanently exposed by a company that collected your data to make money and then, the lawsuit alleges, did not spend what it took to keep it safe.

Legal Receipts

“the [Defendant] failed to reach an agreement with us despite our incredible patience, all the changes and offers we made. They don’t care.”
  • This is the extortion group ShinyHunters’ own public statement, quoted in the complaint, describing a negotiation that 7-Eleven allegedly walked away from.
  • It suggests the company knew its data was stolen and had a chance to keep it off the dark web, and the criminals chose to release all 600,000 records after talks collapsed.
  • The phrase “they don’t care” is the attackers’ framing of the company’s posture toward the people whose data was exposed.
“7-Eleven implements reasonable security measures, procedures and practices in an effort to protect your Personal Information in our possession.”
  • This is 7-Eleven’s own privacy notice, quoted in the complaint’s footnote, the promise it made to customers.
  • The complaint uses it to show the company acknowledged a duty to protect data, then allegedly failed to encrypt or redact any of it.
  • It anchors the breach of implied contract claim: customers were told their information would be protected in exchange for the data.
“In almost all cases, the data breaches that occurred could have been prevented by proper planning and the correct design and implementation of appropriate security solutions.”
  • Quoted from a data breach handbook the complaint cites to establish that breaches are preventable, not inevitable.
  • It frames the core legal theory: this harm resulted from choices and omissions, not from an unstoppable act of criminal genius.

Public Deception

The complaint identifies a gap between what 7-Eleven told customers about data security and what its systems allegedly delivered.

  • 7-Eleven’s privacy notice promised “reasonable security measures, procedures and practices.” The complaint alleges the data was stored completely unencrypted and unredacted.
  • The company represented that it protected personal information in its possession. The complaint alleges it kept thousands of individuals’ sensitive data indefinitely with no business need to retain it.
  • Customers were led to expect industry-standard protection. The complaint alleges 7-Eleven let its security certificates lapse and met the minimum standards of no recognized cybersecurity framework, including NIST and the CIS Critical Security Controls.
What You Were Told vs. The Reality What You Were Told The Reality “Reasonable security measures” Data stored fully unencrypted Information “protected” in possession SSNs, DOBs, licenses left exposed Industry-standard practices Security certificates lapsed Compliance with security frameworks Met minimum of none (NIST, CIS) Data used for business only Data kept indefinitely, no need

Profit-Maximization at All Costs

The complaint alleges 7-Eleven made a financial calculation: it saved money by skipping the security spending it owed to the people whose data it collected.

  • The unjust enrichment claim alleges 7-Eleven “enriched itself by saving the costs it reasonably should have expended on data security measures” to protect the information.
  • The complaint alleges the company “calculated to avoid its data security obligations at the expense of Plaintiff and Class Members by utilizing cheaper, ineffective security measures.”
  • 7-Eleven collects personal data because, per the complaint, it “would be unable to provide its services” without it, meaning the data is a core commercial asset it profited from.
  • The complaint alleges the company “had the resources necessary to prevent the Data Breach but neglected to adequately invest in security measures.”
  • Stolen identity credentials sell for $40 to $200 each on the dark web, and “Fullz” packages can command up to $100 per record, showing the market value 7-Eleven allegedly failed to guard.

How Capitalism Exploits Delay: Time as a Corporate Weapon

The complaint alleges 7-Eleven sat on knowledge of the breach while the people affected stayed in the dark and exposed.

  • The complaint alleges the company “did not notify impacted people for six months after learning of the Data Breach,” calculating from an assumed detection date of November 22, 2025.
  • The complaint cites the FBI’s guidance that “rapid reporting can help law enforcement stop fraudulent transactions before a victim loses the money for good,” and alleges 7-Eleven did the opposite.
  • The complaint alleges the company concealed “the existence and extent of the Data Breach for an unreasonable duration of time.”
  • During that delay, ShinyHunters publicly claimed the breach on April 17, 2026 and made all 600,000 records downloadable, meaning victims learned of exposure from criminals before the company.
Timeline: When Harm Began vs. When People Were Warned Nov 22, 2025 Assumed detection date of breach Apr 17, 2026 ShinyHunters claims breach, posts 600k records ~6 months later Victims notified (per complaint) ~5 months undisclosed

Regulatory Gray Zones

The complaint frames 7-Eleven’s data retention practices as exploiting the absence of hard limits on how long companies can hoard sensitive information.

  • The complaint alleges 7-Eleven kept “thousands of individuals’ unencrypted Private Information on its inadequately secured systems indefinitely,” despite the FTC’s guidance to dispose of data once the business need ends.
  • The FTC guidance quoted in the complaint states: “Keep sensitive data in your system only as long as you have a business reason to have it… If it’s not on your system, it can’t be stolen by hackers.” The complaint alleges the company ignored this.
  • The complaint alleges 7-Eleven failed to meet the minimum standards of NIST frameworks, FEDRAMP, and the CIS Critical Security Controls, none of which carried a mandatory penalty forcing compliance before the breach.

Societal Impact Mapping

Public Health

The complaint documents psychological and medical harm flowing from the exposure of immutable personal data.

  • The plaintiff suffered “emotional distress and increased stress and anxiety” and the knowledge that she “must remain vigilant for the remainder of her life.”
  • The complaint notes identity theft causes “severe distress and other strong emotions and physical reactions” for victims.
  • Stolen data enables medical identity theft, letting criminals impersonate victims to “get medical services,” per the sources cited in the complaint.
  • The complaint describes a permanent, lifelong burden of monitoring accounts and credit that itself imposes ongoing stress on hundreds of thousands of people.

Economic Inequality

The complaint documents financial harms that the people affected must absorb through no fault of their own.

  • Victims face out-of-pocket costs for credit monitoring, which the complaint states can run around $200 per year per person, potentially for life.
  • The complaint alleges lost time and productivity from placing credit freezes, changing passwords, and scanning statements for fraud.
  • A stolen Social Security number can be used for financial identity theft including “false applications for loans, credit cards or bank accounts” and draining existing accounts.
  • Class members lost the diminished market value of their Private Information, which was transferred to criminals “without any consideration paid” to them.
  • The complaint notes class action treatment exists precisely because individuals “could not individually afford to litigate a complex claim against large corporations.”

The “Cost of a Life” Metric

600,000+
records containing names, Social Security numbers, dates of birth, addresses, phone numbers, emails, and driver’s license numbers, allegedly stored unencrypted and now available for download on the dark web.

Who Pays? Following the Cost

The complaint documents a transfer of cost from the company that collected the data to the people whose data was taken.

  • 7-Eleven allegedly saved money by not investing in encryption and security; the people affected now absorb the lifetime cost of protecting themselves.
  • Each class member faces roughly $200 per year in credit and identity-theft monitoring, a “reasonable and necessary” cost the complaint attributes directly to the breach.
  • Class members bear the unpaid labor of placing fraud alerts, freezing credit, and monitoring accounts, described in the complaint as lost time and productivity.
  • The diminished value of their personal data was transferred to hackers with no compensation paid to the people it belonged to.
Cost-Shift: From Corporate Savings to Public Burden 7-Eleven, Inc. Saved on security spending Class Members ~$200/yr monitoring Class Members Lost time, unpaid labor Class Members Diminished data value Cost saved by one company; risk carried by 600,000 people for life.
“They don’t care.”

This Is the System Working as Intended

The complaint’s facts describe a structure where collecting valuable data is profitable and protecting it is optional until a lawsuit forces the question.

  • 7-Eleven allegedly collected data it needed to run its business, profited from it, then “calculated to avoid its data security obligations” by choosing cheaper measures, per the unjust enrichment claim.
  • No mandatory penalty forced compliance beforehand: the complaint alleges the company met the minimum of no recognized framework and let certificates lapse, and only litigation now seeks to compel security upgrades.
  • The complaint alleges the company kept sensitive data indefinitely with no business reason, because there was no hard limit stopping it from hoarding a liability that became a windfall for criminals.
  • The people harmed had “no ability to protect their Private Information,” which was and remains in the company’s possession, leaving them dependent on a company that allegedly did not spend what protection required.

The Settlement Isn’t Justice

No settlement has been reached; the complaint seeks relief because the harm from a Social Security number breach cannot be undone by a one-time payout.

  • A Social Security number is immutable. The complaint notes the government “does not normally replace” it, so no monetary award restores what was taken.
  • Even a new number gets “linked very quickly to the old number,” per the Identity Theft Resource Center quoted in the complaint, meaning the exposure follows victims permanently.
  • The complaint seeks lifetime credit monitoring and forced security overhauls precisely because damages alone leave the underlying risk in place “for the remainder of the lives of Plaintiff and the Class Members.”
  • Any typical data-breach settlement pays fractions of the lifelong monitoring cost, leaving the structural risk uncured while the company retains the savings it allegedly banked.

What a Legitimate Fix Looks Like

Editorial analysis. The core failure this case exposes is a company treating encryption and data disposal as optional costs while profiting from the data it refused to protect.

Regulatory Track

  • The FTC should require mandatory encryption and redaction of Social Security numbers and driver’s license numbers at rest, with enforcement teeth, not voluntary guidance the complaint says was ignored.
  • Regulators should impose hard data-retention limits forcing deletion once a business need ends, directly addressing the alleged indefinite hoarding of unencrypted records.
  • Mandatory breach-notification deadlines should be enforced with penalties, given the complaint’s allegation that 7-Eleven waited roughly six months to notify people. (General industry standard.)

Legislative Track

  • Legislation should make failure to meet a recognized cybersecurity framework, such as NIST or the CIS Controls, a per-se violation, since the complaint alleges the company met the minimum of none.
  • Lawmakers should create a private right of action with statutory damages for unencrypted breaches, so the cost of neglect falls on the company rather than the victims.
  • Statutes should require companies to fund lifetime credit monitoring when Social Security numbers are exposed, matching the permanent nature of the harm the complaint documents.

Corporate Governance Track

  • The board should be required to appoint accountable security leadership with authority over data-retention decisions, given the alleged choice to use “cheaper, ineffective security measures.”
  • 7-Eleven should implement the independent third-party SOC 2 Type 2 audits the complaint requests, on an annual basis for a defined period, with results reported to the court.
  • Executive compensation should tie a portion of pay to documented security compliance, so protecting data becomes a financial priority rather than a cost to be avoided.

What Now?

Direct your attention to the company named in this case and the agencies that set the rules it allegedly ignored.

  • The named defendant is 7-Eleven, Inc., organized in Texas with its principal place of business in Irving, Texas. The case is Choplin v. 7-Eleven, Inc., Case No. 3:26-cv-01754-X, N.D. Tex.
  • Watchlist: the FTC (Section 5 data-security enforcement) and state attorneys general, who hold the authority to pursue the reasonable-security failures this complaint describes.
  • If you shopped 7-Eleven, place a free credit freeze at all three bureaus, set fraud alerts, and monitor your accounts, the same mitigation steps the plaintiff was forced to take.
  • Support and connect with the Identity Theft Resource Center and local consumer-protection clinics that help breach victims navigate recovery without paying out of pocket.
  • Organize with neighbors and coworkers to demand state data-privacy legislation with real penalties, so companies cannot treat your Social Security number as a cost they can skip protecting.

The source document for this investigation is attached below.

Explore by category

01

Antitrust

Monopolies and anti-competition tactics used to crush rivals.

View Cases →
02

Product Safety Violations

When companies sell dangerous goods, consumers pay the price.

View Cases →
03

Environmental Violations

Pollution, ecological collapse, and unchecked greed.

View Cases →
04

Labor Exploitation

Wage theft, worker abuse, and unsafe conditions.

View Cases →
05

Data Breaches & Privacy

Misuse and mishandling of personal information.

View Cases →
06

Financial Fraud & Corruption

Lies, scams, and executive impunity that distort markets.

View Cases →
07

Intellectual Property

IP theft that punishes originality and rewards copying.

View Cases →
08

Misleading Marketing

False claims that waste money and bury critical safety info.

View Cases →
Aleeia
Aleeia

I'm Aleeia, the creator of this website.

I have 6+ years of experience as an independent researcher covering corporate misconduct, sourced from legal documents, regulatory filings, and professional legal databases.

My background includes a Supply Chain Management degree from Michigan State University's Eli Broad College of Business, and years working inside the industries I now cover.

Every post on this site was either written or personally reviewed and edited by me before publication.

Learn more about my research standards and editorial process by visiting my About page

Articles: 2023