Company Details
speedway
18,314
65,296
43
speedway.com
0
SPE_1963302
In-progress

Speedway Company CyberSecurity Posture
speedway.comSpeedway operates across the U.S., predominately in the Midwest and East Coast. In May 2021, 7-Eleven acquired 3,800 Speedway Stores from Marathon Petroleum Corp., increasing 7-Eleven’s total number of stores to more than 13,000 in the U.S. and Canada and allowing 7-Eleven to bring convenience to more customers than ever before. Learn more about 7-Eleven and their family of brands here: https://corp.7-eleven.com/corp/about
Company Details
speedway
18,314
65,296
43
speedway.com
0
SPE_1963302
In-progress
Between 700 and 749

Speedway Global Score (TPRM)XXXX

Description: The Vermont Office of the Attorney General reported a data breach involving Speedway on May 16, 2023. The breach was discovered on April 11, 2023, when unauthorized parties accessed Speedy Rewards accounts, potentially affecting names, email addresses, points balances, and additional account information. Approximately 163 individuals in Rhode Island were specifically affected by this incident.
Description: The Maine Office of the Attorney General reported a data breach involving Speedway LLC on May 16, 2023. The breach, which involved a credential stuffing attack, was discovered on April 17, 2023, and impacted approximately 3 individuals. Unauthorized access may have exposed customer names, email addresses, and account information including points balance.


No incidents recorded for Speedway in 2025.
No incidents recorded for Speedway in 2025.
No incidents recorded for Speedway in 2025.
Speedway cyber incidents detection timeline including parent company and subsidiaries

Speedway operates across the U.S., predominately in the Midwest and East Coast. In May 2021, 7-Eleven acquired 3,800 Speedway Stores from Marathon Petroleum Corp., increasing 7-Eleven’s total number of stores to more than 13,000 in the U.S. and Canada and allowing 7-Eleven to bring convenience to more customers than ever before. Learn more about 7-Eleven and their family of brands here: https://corp.7-eleven.com/corp/about


H-E-B is headquartered in San Antonio, Texas with approximately $32 billion in revenue and 117,000+ Partners. Founded in 1905, H-E-B operates more than 400 stores in a number of formats, including superstores, supermarkets and gourmet markets. H-E-B is the #1 food retailer in the Austin, San Antoni

H&R Block’s purpose is simple: To provide help and inspire confidence in our clients and communities everywhere. We’ve been true to that purpose since brothers Henry and Richard Bloch founded our company in 1955. Since then, we’ve prepared approximately 800 million tax returns and grown to have appr

Sprouts is the place where goodness grows. True to its farm-stand heritage, Sprouts offers a unique grocery experience featuring an open layout with fresh produce at the heart of the store. Sprouts inspires wellness naturally with a carefully curated assortment of better-for-you products paired wit

Ahold Delhaize is one of the world’s largest food retail groups, we are a leader in supermarkets and e-commerce, and a company at the forefront of sustainable retailing. Our local brands employ around 393,000 associates in around 9,400 local grocery, small format, and specialty stores. Our family

Somos a RD Saúde, um ecossistema de saúde integral, com mais de 3 mil farmácias em todo o Brasil e negócios em saúde que dividem o mesmo propósito: contribuir para uma sociedade mais saudável. Nossa jornada começou em novembro de 2011, fruto da união entre Droga Raia e Drogasil, crescendo até se tor

Arbonne, creates personal skincare and wellness products that are crafted with premium botanical ingredients and innovative scientific discovery. Delivering on the Company’s commitment to pure, safe and beneficial products, Arbonne’s personal care and nutrition formulas are vegan certified and adher
Wayfair is the destination for all things home: helping everyone, anywhere create their feeling of home. From expert customer service, to the development of tools that make the shopping process easier, to carrying one of the widest and deepest selections of items for every space, style, and budget,

Компания NO ONE более 20 лет занимает лидирующие позиции в розничном сегменте. NO ONE – один из крупнейших дистрибьюторов обуви и аксессуаров ведущих европейских брендов на российском рынке. В портфеле компании NO ONE около 50 европейских марок: Casadei, Fabi, Vicini, Baldinini, Braccialini, Gi

As one of only two national grocery retailers in Canada, Sobeys Inc. serves the food shopping needs of Canadians with more than 1,500 stores in 10 provinces with retail banners that include Sobeys, Safeway, IGA, Foodland, FreshCo, Price Chopper, Thrifty Foods and Lawtons Drugs, as well as more than
.png)
An Illinois federal judge on Wednesday granted final approval for a $12.1 million class action settlement in a Biometric Information Privacy...
Demolition began Monday morning at the old Homecoming Restaurant, located at 1330 U.S. Route 68 North on the northern edge of Bellefontaine.
GREENWIRE | MIAMI — U.S. District Judge Kathleen Williams sharply questioned lawyers for the state of Florida and federal government...
CONCORD, N.C. – Hendrick Motorsports has added leading cybersecurity provider Atlantic Data Security (ADS) as a new technology partner in a...
An Illinois federal judge gave preliminary approval for a $12.1 million class action settlement in a biometric privacy law dispute between...
Fans of Richard Childress Racing may have noticed a new logo on the A Post of the race team's iconic No. 3 Chevrolet this season.
Embry-Riddle Aeronautical University student Marc Jacquet has investigated this hypothetical scenario, applying artificial intelligence to study the effects of...
Forte Racing is thrilled to announce that Huntress, the cybersecurity company protecting businesses of all sizes, has expanded its...
We had the distinct privilege of sitting down with Kyle Hanslovan, Co-Founder and CEO of Huntress, as he gears up to make waves in two...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Speedway is http://speedway.com/careers.
According to Rankiteo, Speedway’s AI-generated cybersecurity score is 739, reflecting their Moderate security posture.
According to Rankiteo, Speedway currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Speedway is not certified under SOC 2 Type 1.
According to Rankiteo, Speedway does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Speedway is not listed as GDPR compliant.
According to Rankiteo, Speedway does not currently maintain PCI DSS compliance.
According to Rankiteo, Speedway is not compliant with HIPAA regulations.
According to Rankiteo,Speedway is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Speedway operates primarily in the Retail industry.
Speedway employs approximately 18,314 people worldwide.
Speedway presently has no subsidiaries across any sectors.
Speedway’s official LinkedIn profile has approximately 65,296 followers.
Speedway is classified under the NAICS code 43, which corresponds to Retail Trade.
No, Speedway does not have a profile on Crunchbase.
Yes, Speedway maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/speedway.
As of November 27, 2025, Rankiteo reports that Speedway has experienced 2 cybersecurity incidents.
Speedway has an estimated 15,251 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Cyber Attack.
Title: Speedway Data Breach
Description: Unauthorized parties accessed Speedy Rewards accounts, potentially affecting names, email addresses, points balances, and additional account information.
Date Detected: 2023-04-11
Date Publicly Disclosed: 2023-05-16
Type: Data Breach
Title: Speedway LLC Data Breach
Description: The Maine Office of the Attorney General reported a data breach involving Speedway LLC on May 16, 2023. The breach, which involved a credential stuffing attack, was discovered on April 17, 2023, and impacted approximately 3 individuals. Unauthorized access may have exposed customer names, email addresses, and account information including points balance.
Date Detected: 2023-04-17
Date Publicly Disclosed: 2023-05-16
Type: Data Breach
Attack Vector: Credential Stuffing
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names, Email addresses, Points balances, Additional account information

Data Compromised: Customer names, Email addresses, Account information including points balance
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Email Addresses, Points Balances, Additional Account Information, , Customer Names, Email Addresses, Account Information Including Points Balance and .

Entity Name: Speedway
Entity Type: Company
Industry: Retail
Customers Affected: 163

Entity Name: Speedway LLC
Entity Type: Company
Industry: Retail
Customers Affected: 3

Type of Data Compromised: Names, Email addresses, Points balances, Additional account information
Number of Records Exposed: 163
Personally Identifiable Information: namesemail addresses

Type of Data Compromised: Customer names, Email addresses, Account information including points balance
Number of Records Exposed: 3
Personally Identifiable Information: Customer namesEmail addresses

Source: Vermont Office of the Attorney General
Date Accessed: 2023-05-16

Source: Maine Office of the Attorney General
Date Accessed: 2023-05-16
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Vermont Office of the Attorney GeneralDate Accessed: 2023-05-16, and Source: Maine Office of the Attorney GeneralDate Accessed: 2023-05-16.
Most Recent Incident Detected: The most recent incident detected was on 2023-04-11.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-05-16.
Most Significant Data Compromised: The most significant data compromised in an incident were names, email addresses, points balances, additional account information, , Customer names, Email addresses, Account information including points balance and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Email addresses, points balances, Customer names, email addresses, names, additional account information and Account information including points balance.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 166.0.
Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General and Vermont Office of the Attorney General.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.