Share

In 1927, a man named John Jefferson Green walked up to Joe C. Thompson at a Dallas ice dock and asked if he could sell milk, eggs, and bread alongside the block ice. Thompson said yes, and together they accidentally invented the convenience store. That company became the Southland Ice Company, then the Tote’m Stores, and eventually 7-Eleven, a name nearly every person in America grew up with. Nearly a century later, 7-Eleven operates over 85,000 stores worldwide and is owned by Japan’s Seven & i Holdings.

On April 8, 2026, a different kind of customer decided to help themselves to something bigger than a Slurpee and a lottery ticket. ShinyHunters, a financially motivated extortion group active since 2020 and responsible for breaches at Ticketmaster, AT&T, Google, Vimeo, and hundreds of other organizations, accessed 7-Eleven’s Salesforce environment and claimed to have stolen more than 600,000 records. A company built on the promise of trust and accessibility had that trust broken by an attacker who did not need to be particularly clever, because the front door was already open.

How a misconfigured guest user profile became a 185,000-person breach

The attack did not involve a zero-day exploit or nation-state tooling. Mandiant confirmed that 7-Eleven was part of a broader ShinyHunters campaign systematically scanning Salesforce Experience Cloud sites since September 2025, exploiting a known configuration weakness rather than a bug in Salesforce’s code. The group used a modified version of AuraInspector, a defensive auditing tool that Mandiant itself released in January 2026 to help administrators find misconfigurations in the Salesforce Aura framework. ShinyHunters took that tool, modified it to extract data rather than just identify exposure, and pointed it at orgs across the internet.

The attack targeted the /s/sfsites/aura API endpoint exposed on public Experience Cloud sites. When a guest user profile has excessive permissions, that endpoint allows unauthenticated visitors to query CRM objects directly without logging in. The modified variant also exploited Salesforce’s GraphQL interface, bypassing the roughly 2,000-record limit of older techniques to enable extraction at scale. In 7-Eleven’s case, systems storing franchisee application documents were accessible through an overly permissive guest user configuration. The stolen records included names, dates of birth, addresses, phone numbers, emails, Social Security numbers, and driver’s license numbers, as confirmed in state filings in Maine, Vermont, and Massachusetts.⁷ Have I Been Pwned listed 185,300 unique affected individuals.

ShinyHunters set a ransom deadline of April 21. When 7-Eleven refused to pay, the group published a 9.4-gigabyte archive and listed the data for $250,000 on an underground forum. The FBI issued IC3 Alert I-051526-PSA on May 15, warning about ShinyHunters and advising victims not to pay.

What 7-Eleven could have done before April 8

Salesforce published a security advisory on March 7, 2026, more than a month before the intrusion, explicitly warning customers about this exact campaign. The advisory was updated on March 11 with additional steps. The guidance was specific, actionable, and free.

The single highest-impact change, per Salesforce’s advisory, is to disable the “API Enabled” permission on the guest user profile. That one checkbox closes the Aura endpoint to unauthenticated queries, which was the exact vector used. Beyond that, Salesforce recommended setting OWDs to Private for external users, unchecking “Allow guest users to access public APIs,” disabling Portal User Visibility and Site User Visibility, and reviewing Event Monitoring logs.⁵ FINRA issued its own alert reinforcing the same guidance. Every one of these steps was available before April 8. Every one is available to your org right now.

The shared responsibility model has a communication problem

Salesforce operates under a shared responsibility model, and the platform itself was not compromised. The challenge is not the model. The challenge is that communication around it has not kept pace with the threats targeting customer configurations.

There is a brand trust bias in the Salesforce ecosystem that works against security outcomes. When you trust a platform deeply, and the ecosystem reinforces that trust at every turn, the natural assumption is that default configurations are safe configurations. They are not. Salesforce gives customers enormous flexibility in how they configure access, and that flexibility requires active, ongoing security governance that most orgs have never resourced.

Could the communication from Salesforce be more aggressive, more urgent, more impossible to miss? It absolutely could be. Salesforce published a blog post and Trust site advisory, and directly notified customers confirmed to be impacted. That is responsible. It is also easy to miss if your team is not actively monitoring those channels, and the orgs most likely to have misconfigured guest user profiles are the same orgs least likely to have someone watching the Salesforce security blog. Salesforce has started to move in this direction with its June 2026 security enforcement wave, including MFA enforcement for all user logins across production and sandbox orgs. That is a meaningful step. It also comes after ShinyHunters compromised roughly 760 Salesforce orgs through the Salesloft/Drift OAuth campaign and more than 200 through Gainsight in 2025 alone, then hit 300 to 400 more through the Aura campaign in early 2026.

AI-powered threats make the fundamentals non-negotiable

The organizations that survive the future of AI-powered attacks will not be the ones with the most advanced tooling alone. They will be the ones who also understand Salesforce security fundamentals. AI is collapsing the time between vulnerability discovery and exploitation: from 2.3 years in 2018 to 20 hours in 2026. Jailbroken open-weight models and autonomous AI pentesters are now available to anyone with a browser. The IBM 2025 Cost of a Data Breach Report puts the global average at $4.44 million, with U.S. breaches averaging $10.22 million. For 7-Eleven specifically, the financial exposure is stacking up fast. The company has committed to 24 months of IDX identity theft monitoring for all affected individuals, with enrollment open through August 1, 2026. Multiple law firms have announced class action investigations, and comparable data breach settlements in the past year have ranged from $725,000 to $31.5 million. That figure does not include forensic investigation costs, system remediation, regulatory fines from state attorneys general in Maine and Massachusetts, or the long-term franchise recruitment damage that comes from having prospective franchisees’ Social Security numbers published on the dark web.

In this environment, an unchecked guest user profile is not a low-priority backlog item. It is an open invitation that AI-powered scanning tools will find faster than any human attacker ever could.

The accountability question nobody wants to answer

The pattern repeats because the gap repeats. Someone configures an Experience Cloud site under deadline pressure. Permissions get opened wide to make features work. Nobody schedules the follow-up audit. Nobody owns the guest user profile after go-live. The org drifts. The Health Check score drops. The security advisory lands in an inbox nobody monitors.

This is not an admin problem. This is an organizational accountability problem. There is no continuous monitoring of configuration drift in most Salesforce orgs. There is no system that flags when a guest user profile gains permissions it should not have. There is no accountability layer between the advisory Salesforce publishes and the action the org takes, or fails to take. The tools exist. The documentation exists. What does not exist in most organizations is a clear answer to one question: who is responsible for knowing that your Salesforce security posture changed, and what are they supposed to do about it?

Until that question has a name, a process, and a cadence attached to it, breaches like this one will keep happening. The platform did not fail. The admin did not fail. The organization never assigned the job.

What to do this week

If you read one section of this post and act on it, make it this one. These are the specific steps your team can take right now, most of them inside Setup, to close the exact exposure that cost 7-Eleven 185,000 people their Social Security numbers and counting.

Your Salesforce org deserves the same discipline as a doctor’s annual physical, and that discipline should not start when symptoms appear or after a breach notification lands. It should start now. If your team does not have the capacity or the confidence to run a full security assessment internally, book one with someone who does. The configurations are knowable. The risks are preventable. The only thing standing between your org and the next breach notification is the decision to look.

Book a security assessment to see how your org’s security posture stands up (and what to do next). 

Frequently Asked Questions

Was Salesforce itself hacked in the 7-Eleven breach?

No. Salesforce’s platform was not compromised. The breach resulted from a misconfigured Experience Cloud guest user profile that gave unauthenticated visitors access to CRM data through the Aura API endpoint. Salesforce published a security advisory on March 7, 2026, more than a month before the 7-Eleven intrusion, warning customers about this exact campaign and providing specific remediation steps.

What is AuraInspector and how was it used in this attack?

AuraInspector is an open-source auditing tool developed by Mandiant (Google Threat Intelligence Group) in January 2026 to help administrators find access control misconfigurations in the Salesforce Aura framework. ShinyHunters modified the tool to extract data rather than just identify exposure, then used it to mass-scan publicly accessible Experience Cloud sites. The modified variant also exploited Salesforce’s GraphQL interface to bypass the roughly 2,000-record limit of older extraction techniques.

How much will the 7-Eleven breach cost?

Final costs are not yet determined, but the financial exposure is significant. The IBM 2025 Cost of a Data Breach Report puts the average U.S. breach at $10.22 million. For 7-Eleven specifically, costs include 24 months of IDX identity theft monitoring for 185,300 affected individuals, forensic investigation and system remediation, regulatory fines from multiple state attorneys general, and class action liability. Comparable data breach settlements in the past year have ranged from $725,000 to $31.5 million.

What is the single most important thing I can do in Salesforce Setup right now?

Disable the “API Enabled” permission on the guest user profile. Per Salesforce’s own advisory, this is the highest-impact single change you can make. It closes the Aura endpoint to unauthenticated API queries, which was the exact attack vector used in the ShinyHunters campaign. Then run Salesforce Health Check and document your score.

Why do breaches like this keep happening if the fixes are available?

Because most organizations have no accountability layer between a security advisory being published and the configuration change actually being made. Someone has to own the guest user profile after go-live. Someone has to monitor for configuration drift. Someone has to be accountable for quarterly reviews. In most Salesforce orgs, that role does not exist, and the result is a widening gap between what the org should be doing and what it is actually doing. That gap is exactly where attackers like ShinyHunters operate.

What is EzProtect and how does it help with Salesforce security?

EzProtect is a Salesforce security company focused on closing the accountability gap that leads to breaches like the one at 7-Eleven. EzProtect provides security assessments, ongoing threat protection, and a security incident response platform called Argus that gives organizations continuous visibility into their Salesforce security posture with enforced accountability milestones. Argus is designed to ensure that when a configuration drifts, a permission changes, or a security advisory lands, someone in the org is responsible for acting on it, and there is a system that verifies they did.

How is Argus different from Salesforce Health Check or Security Center?

Salesforce Health Check is a free, built-in tool that scores your org’s configuration at a point in time. Security Center provides visibility across multiple orgs. Both are valuable, but neither enforces accountability. They tell you what is wrong. They do not assign ownership, set deadlines, require a reviewer and approver, or track whether the fix actually happened. Argus closes that gap with enforced accountability milestones, 360-degree visibility, and a response workflow designed for organizations that do not yet have a mature security function. It is the difference between knowing you have a problem and having a system that makes sure someone solves it.

Where can I learn more about Salesforce security threats and best practices?

Salesforce Security Office Hours, hosted by Matt Meyers, is a free educational series featuring Salesforce CTAs, architects, and security practitioners breaking down real-world threats, attack vectors, and defensive strategies. Past sessions have covered the ShinyHunters Aura campaign, AI-powered threats to Salesforce, Agentforce security architecture, and breach communication strategies for the C-suite. Subscribe to the Salesforce Security Blog and Salesforce Security Advisories for official updates.

By Published On: June 5, 2026Categories: Argus, Blog, Cybersecurity, Salesforce Admins0 Comments

Share

Did you love this blog and wish there could be more?

It is our goal to keep you informed about everything you need to know about Salesforce security to keep your Salesforce data and company safe and secure by providing you with the highest quality of original content.

If this sounds good to you, then sign-up below to be one of the first to know when the next super awesome Salesforce security blog has been released.

Download your free guide today!

Learn if you are at risk and how to start protecting your users!

GET THE FACTS NOW