Skip to main content
Back to overview
High

Krispy Kreme says November data breach impacts over 160,000 people

Coverage on some of the most important topics in healthcare, like HIPAA compliance, and secure and encrypted email.

Key points

  • Cyberattack occurred in November 2024, with some sources citing November 19, 2024, as the breach date.
  • Unauthorized activity detected on November 29, 2024.
  • Over 160,000 individuals (specifically 161,676) affected.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Malware, Social, Hacking, Error activity

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Nov 19, 2024
Updated
Jul 22, 2026
Confidence
High
Evidence
4 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Malware, Social, Hacking, Error activity

The feed marks multiple actor roles. Treat this as a review signal rather than a final attribution.

  • Source type: possible insider or internal misuse
  • Source type: supplier or third-party involvement

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

KrispykremeData DisclosureKrispy KremeCoverageHIPAAGentlemenPhishingGmailPassword-protected PDFsMicrosoft

Quick context

Questions about this signal

What happened in this signal?

Coverage on some of the most important topics in healthcare, like HIPAA compliance, and secure and encrypted email. Gentlemen ransomware turns infected devices into a network-wide worm Phishing campaign posing as job recruiters, stealing Gmail passwords Password-protected PDFs are new entry point for Microsoft account takeover Medtronic notifies patients as breach scope reaches nearly 370k DOJ charges trio behind network tied to $62M in cybercrime losses US offers $10M reward for Russian hackers who steal Signal backup keys Spanish authorities dismantle $160 million cyber fraud Madison Square Garden is the newest victim of ShinyHunters California begins implementing first-in-nation Delete Act Watchdog finds veteran communication system exposed medical records Phishing kit hijacks Microsoft 365 accounts to defeat spam filters BEC phishing kit adds inbox rule manipulation to Microsoft 365 attacks Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster. Krispy Kreme breach, data theft claimed by Play ransomware gang ​The Play ransomware gang has claimed responsibility for a cyberattack that impacted the business operations of the U.S. doughnut chain Krispy Kreme in November. Krispy Kreme disclosed the incident and subsequent disruptions to its online ordering system in an SEC filing submitted on December 11. The company detected unauthorized activity on some of its information technology systems on November 29. After the attack, Krispy Kreme also took measures to contain and remediate the breach and hired external cybersecurity experts to investigate the attack's impact and scope. "We're experiencing certain operational disruptions due to a cybersecurity incident, including with online ordering in parts of the United States," Krispy Kreme said in a message on its official website. "We know this is an inconvenience and are working diligently to resolve the issue. [..] We'll have our online ordering up as soon as we can. Our fresh doughnuts are available in our shops as always!" Krispy Kreme's Q3 2024 financial results show that digital orders represent 15.5% of the company's sales, contributing to its 3.5% organic revenue growth in Q3 2024. The American multinational coffeehouse chain and doughnut company operates 1,521 shops and 15,800 points of access, four "Doughnut Factories" in the United States, and 37 others internationally. As of December 2023, it employed 22,800 people in 40 countries. Krispy Kreme also partners with McDonald's to have its products sold in thousands of additional McDonald's locations worldwide. While the company has yet to share additional details about the attack and, when approached by BleepingComputer for comment, shared a statement similar to the one filed with the SEC, the Play ransomware gang has now claimed the November breach and says they also allegedly stole data from the company's network. Play ransomware claims, without proof, that they collected and stole files containing "private and personal confidential data, client documents, budget, payroll, accounting, contracts, taxes, IDs, finance information," and more. The attackers now say they'll publish the data this Saturday, December 21. The Play ransomware operation surfaced over two years ago, in June 2022, with initial victims seeking help through BleepingComputer's forums . Play operators steal sensitive data from breached systems to use in double-extortion schemes, pressuring victims into paying ransoms to avoid having the stolen data leaked online. Previous notable Play ransomware victims include car retailer giant Arnold Clark , cloud computing company Rackspace , the City of Oakland in California, Dallas County , the Belgian city of Antwerp , and, most recently, American semiconductor supplier Microchip Technology . The FBI issued a joint advisory with CISA and the Australian Cyber Security Centre (ACSC) last December, warning that the Play ransomware operation had breached the networks of around 300 organizations worldwide as of October 2023. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen. The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak Hugging Face warns an autonomous AI agent hacked its network Lidl discloses online shop breach after service provider hack Insurance giant Aflac discloses data breach after subsidiary hack Infinite Campus data breach affects 137,000 school staff accounts

When was this signal reported?

Shadow Tier lists Nov 19, 2024 as the signal date.

Which organization is connected to this signal?

Krispykreme is the organization connected to this public signal.

Explore Krispykreme
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence