WK Kellogg confirms employee data breach tied to Cleo file transfer flaws

Organization
WK Kellogg Co.
Exploit
Supply Chain Attack
Industry
Food and Beverage Manufacturing

WK Kellogg Co., the Battle Creek, Michigan cereal maker spun out of Kellogg Company in 2023, confirmed in April 2025 that employee data had been taken from servers running Cleo managed file transfer software.

In a filing with the Maine Attorney General dated April 4, 2025, the company said the servers, used to move employee files to human resources service vendors, were accessed on December 7, 2024. WK Kellogg said it did not learn of the intrusion until February 27, 2025, nearly three months later.

The compromise stemmed from flaws in Cleo's Harmony, VLTrader and LexiCom products, tracked as CVE-2024-50623 and CVE-2024-55956. Researchers found that Cleo's October 2024 patch for the first flaw was incomplete, leaving customers exposed to continued exploitation. The Clop ransomware group claimed a broad campaign against organizations running Cleo software and listed WK Kellogg on its dark web leak site in February 2025. Mandiant researchers tied a cluster of the activity to the threat actor they track as FIN11, which overlaps with Clop.

The Maine filing described the exposure of a name and Social Security number belonging to a single resident of that state. WK Kellogg did not publish a nationwide total. The company began mailing notification letters and offered affected individuals a year of identity monitoring, credit monitoring and fraud restoration services through Kroll. Cybersecurity Dive reported that a company spokesperson was not immediately available for comment.

Sources