1
Published signals
currently linked to this company
Company intelligence
krispykreme.com
This company page brings together public reporting currently associated with Krispykreme. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
0
recent published signals
0
recent published signals
1
confidence classifications
July 22, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Krispykreme. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
Coverage on some of the most important topics in healthcare, like HIPAA compliance, and secure and encrypted email. Gentlemen ransomware turns infected devices into a network-wide worm Phishing campaign posing as job recruiters, stealing Gmail passwords Password-protected PDFs are new entry point for Microsoft account takeover Medtronic notifies patients as breach scope reaches nearly 370k DOJ charges trio behind network tied to $62M in cybercrime losses US offers $10M reward for Russian hackers who steal Signal backup keys Spanish authorities dismantle $160 million cyber fraud Madison Square Garden is the newest victim of ShinyHunters California begins implementing first-in-nation Delete Act Watchdog finds veteran communication system exposed medical records Phishing kit hijacks Microsoft 365 accounts to defeat spam filters BEC phishing kit adds inbox rule manipulation to Microsoft 365 attacks Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster. Krispy Kreme breach, data theft claimed by Play ransomware gang The Play ransomware gang has claimed responsibility for a cyberattack that impacted the business operations of the U.S. doughnut chain Krispy Kreme in November. Krispy Kreme disclosed the incident and subsequent disruptions to its online ordering system in an SEC filing submitted on December 11. The company detected unauthorized activity on some of its information technology systems on November 29. After the attack, Krispy Kreme also took measures to contain and remediate the breach and hired external cybersecurity experts to investigate the attack's impact and scope. "We're experiencing certain operational disruptions due to a cybersecurity incident, including with online ordering in parts of the United States," Krispy Kreme said in a message on its official website. "We know this is an inconvenience and are working diligently to resolve the issue. [..] We'll have our online ordering up as soon as we can. Our fresh doughnuts are available in our shops as always!" Krispy Kreme's Q3 2024 financial results show that digital orders represent 15.5% of the company's sales, contributing to its 3.5% organic revenue growth in Q3 2024. The American multinational coffeehouse chain and doughnut company operates 1,521 shops and 15,800 points of access, four "Doughnut Factories" in the United States, and 37 others internationally. As of December 2023, it employed 22,800 people in 40 countries. Krispy Kreme also partners with McDonald's to have its products sold in thousands of additional McDonald's locations worldwide. While the company has yet to share additional details about the attack and, when approached by BleepingComputer for comment, shared a statement similar to the one filed with the SEC, the Play ransomware gang has now claimed the November breach and says they also allegedly stole data from the company's network. Play ransomware claims, without proof, that they collected and stole files containing "private and personal confidential data, client documents, budget, payroll, accounting, contracts, taxes, IDs, finance information," and more. The attackers now say they'll publish the data this Saturday, December 21. The Play ransomware operation surfaced over two years ago, in June 2022, with initial victims seeking help through BleepingComputer's forums . Play operators steal sensitive data from breached systems to use in double-extortion schemes, pressuring victims into paying ransoms to avoid having the stolen data leaked online. Previous notable Play ransomware victims include car retailer giant Arnold Clark , cloud computing company Rackspace , the City of Oakland in California, Dallas County , the Belgian city of Antwerp , and, most recently, American semiconductor supplier Microchip Technology . The FBI issued a joint advisory with CISA and the Australian Cyber Security Centre (ACSC) last December, warning that the Play ransomware operation had breached the networks of around 300 organizations worldwide as of October 2023. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak Hugging Face warns an autonomous AI agent hacked its network Lidl discloses online shop breach after service provider hack Insurance giant Aflac discloses data breach after subsidiary hack Infinite Campus data breach affects 137,000 school staff accounts
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Krispykreme.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.