Krispy Kreme Cyberattack Exposes Personal Data of 161,676 Customers


# Krispy Kreme Confirms Data Breach Affecting Over 160,000 Customers

Popular doughnut chain Krispy Kreme has confirmed that cybercriminals stole personal information from more than 160,000 individuals during a November 2024 cyberattack. The company, which operates 1,521 shops across 40 countries and employs 22,800 people worldwide, disclosed the breach details in regulatory filings this week.

## Breach Details and Timeline

Krispy Kreme detected unauthorized activity on its IT systems on November 29, 2024, and initially reported the incident to the Securities and Exchange Commission on December 11. The attack disrupted the company’s online ordering systems and prompted immediate containment measures.

According to breach notification letters sent to affected customers, exactly 161,676 individuals had their personal information compromised. The stolen data included highly sensitive information such as:

– Social Security numbers
– Financial account information
– Driver’s license details

Despite the severity of the data exposure, Krispy Kreme stated there is currently no evidence of information misuse or reports of identity theft directly linked to this incident.

## Play Ransomware Claims Responsibility

The Play ransomware group claimed responsibility for the attack in late December 2024. The cybercriminal organization alleged they stole extensive corporate data including client documents, payroll information, accounting records, contracts, and tax documents.

After failed negotiations with Krispy Kreme, the ransomware gang published hundreds of gigabytes of stolen documents on their dark web leak site on December 21, 2024. This follows Play ransomware’s typical double-extortion strategy of stealing data and threatening public release to pressure victims into paying ransoms.

## Growing Threat from Play Ransomware

The Play ransomware operation, which emerged in June 2022, has become a significant cybersecurity threat. The group has targeted numerous high-profile organizations including cloud provider Rackspace, car retailer Arnold Clark, the City of Oakland, Dallas County, and semiconductor company Microchip Technology.

In December 2024, the FBI, along with CISA and the Australian Cyber Security Centre, issued a joint advisory warning that Play ransomware had compromised approximately 300 organizations globally as of October 2023, with the number likely reaching 900 victims including critical infrastructure organizations.

## Company Response

Krispy Kreme has engaged external cybersecurity experts to assess the full impact of the attack and implement additional security measures. The company continues to monitor for any signs of data misuse while working to strengthen its cybersecurity defenses against future attacks.

This incident highlights the ongoing vulnerability of major retail chains to sophisticated ransomware attacks and the importance of robust cybersecurity measures in protecting customer data.

Share This Article