Krispy Kreme breach exposed data on 161,676 people after 2024 attack

Organization
Krispy Kreme
Exploit
Ransomware
Industry
Food & Beverage

Krispy Kreme began notifying individuals in June 2025 that personal information had been taken during a cyberattack on its corporate network the previous November. The doughnut chain first disclosed the intrusion in December 2024, when unauthorized activity on its systems disrupted online ordering across parts of the United States.

Breach filings put the number of affected people at 161,676. Krispy Kreme said its investigation into what had been taken concluded on May 22, 2025. Most of those notified were current and former employees and members of their families rather than customers.

The exposed categories were unusually broad. According to the notification letters, they included names, dates of birth, Social Security numbers, driver's license and passport numbers, financial account numbers and login credentials, payment card numbers with security codes, digital signatures, biometric data, USCIS alien registration numbers, military identification numbers, and health insurance and medical information.

The Play ransomware group claimed the attack in December 2024, said it had taken 184 GB of data, and published the files on its leak site. Krispy Kreme did not state publicly whether ransomware was involved. The company offered those affected free credit monitoring and identity protection, said it had strengthened its security, and reported no evidence that the information had been misused. Cost estimates varied by outlet, from roughly $5 million in losses plus $4.4 million in remediation to a figure of about $11 million.

Sources