logo

Glazed and confused: Hole lotta highly sensitive data nicked from Krispy Kreme

ID: a7ebd968-4cca-52dc-8ed8-1fce8c949ae0

STIX ID: report--a7ebd968-4cca-52dc-8ed8-1fce8c949ae0

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-06-19

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Krispy Kreme disclosed a November 29, 2024 cybersecurity incident that impacted 161,676 individuals—primarily current and former employees and family members—exposing extensive sensitive data including names, SSNs, dates of birth, passports, driver’s licenses, biometric data, financial account details and credentials, medical information, and more; the company reported roughly $4.4M in cleanup costs and an estimated $5M EBITDA impact, offered 12 months of credit monitoring and identity protection, and noted that the Play ransomware group claimed responsibility though there is no public evidence of misuse to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.