
U.S. doughnut chain Krispy Kreme said the data security incident it suffered last year compromised the sensitive personal information of more than 160,000 individuals.
Headquartered in Charlotte, North Carolina, Krispy Kreme is an American multinational doughnut company and coffeehouse chain. With more than 1,500 shops, the company partners with McDonalds to offer its products at several other locations.
In a data security incident notice published on its website, Krispy Kreme said that on November 29, it was notified about an unauthorised activity in portions of its internal network. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. It also took steps to contain and remediate the incident and notified relevant law enforcement authorities about the same.
On May 22, the investigation concluded that the sensitive personal data of its customers and staff was compromised during the incident. The affected data included names, Social Security numbers, dates of birth, driver’s license or state ID numbers, financial account information, usernames and passwords to financial accounts, passport numbers, digital signatures, and more.
In a filing with the Office of Maine Attorney General, Krispy Kreme said that it has identified at least 161,676 individuals affected by the data security incident.
While Krispy Kreme found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered one year of complimentary identity protection and credit monitoring services through Kroll to all affected individuals.
Krispy Kreme was hacked by Play Ransomware. pic.twitter.com/tQD1ZKiDSf
— Dominic Alvieri (@AlvieriD) December 19, 2024
In December, the Play ransomware group claimed responsibility for the cyber attack on Krispy Kreme and listed it as a victim on its data leak site. The group claimed to have access to the company’s database including client files, budget, payroll, accounting, contracts, taxes, identification documents and finances and threatened to leak the same on December 21 unless its ransom demands weren’t met
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543