Krispy Kreme Data Breach Affects Consumer Info

Published
June 17, 2025
Updated
July 1, 2025
Krispy Kreme Data Breach Affects Consumer Info
Krispy Kreme
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Krispy Kreme

data breach?

Join the Lawsuit

It's free to join. 

Krispy Kreme Doughnut Corporation experienced a cybersecurity attack that impacted it's online ordering system, which remained disrupted for several days. The data breach was discovered on November 29, 2024.

According to news reports, it took approximately one month to resolve the system error disruption due to unauthorized activity. An investigation was launched and on May 22, 2025 it was determined that the personal information of 162,676 individuals.

Exposed customer and employee information may include name, Social Security number, date of birth, driver’s license or state ID number, financial account information, financial account access information, credit or debit card information, credit or debit card information in combination with a security code, username and password to a financial account, passport number, digital signature, username and password, email address and password, biometric data, USCIS or Alien Registration Number, US military ID number, medical or health information, and health insurance information.

Affected employees and customers include 179 Massachusetts residents, 21 Mainers, 7,266 South Carolina residents and 6,948 Texans.

Krispy Kreme filed a cybersecurity incident report with the SEC on December 11, 2024. The data breach was disclosed to the California, Maine, South Carolina, New Hampshire, Vermont, Texas and Massachusetts Attorney Generals' offices beginning on June 17, 2025.

Krispy Kreme's response

Krispy Kreme initiated an investigation and notified law enforcement. Krispy Kreme has notified affected individuals and published a Notice of Data Breach on its own website.

If you have received a data breach notification from Krispy Kreme, you may want to:

  • Sign up for the Kroll identity monitoring services offered, paid for by Krispy Kreme.
  • Monitor your credit reports and financial accounts for any unusual activity.
  • Be alert for phishing emails or phone calls that may use your exposed information.
  • Consider placing a fraud alert or credit freeze with major credit bureaus.

To learn more about the company, visit the Krispy Kreme website.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Krispy Kreme
Consumers Notification date
June 16, 2025
Date of Breach
Breach Discovered Date
May 22, 2025
Total People Affected
161676
Information Types Exposed
  • name
  • Social Security number
  • date of birth
  • driver’s license or state ID number
  • financial account information
  • financial account access information
  • credit or debit card information
  • credit or debit card information in combination with a
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image