Krispy Kreme Doughnut Corporation
bd_19e91671f3e66bc8 · schema v1 · pii pii-v1
Full breach record for Krispy Kreme Doughnut Corporation →Krispy Kreme Doughnut Corporation notified Vermont consumers of a data security incident discovered on November 29, 2024. Unauthorized activity on IT systems led to the compromise of personal information. The company engaged cybersecurity experts and law enforcement, and is offering complimentary identity monitoring services through Kroll. No evidence of misuse was found as of the notification date.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 29, 2024
Discovered
Jun 16, 2025
Filed
vs. sector median
+21 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Indiana State AGbd_0d261f83a1177f1a2025-06-16Verified
- Delaware State AGbd_f982d429044108292025-06-16Verified
- Massachusetts State AGbd_65362ff1582efe022025-06-17 · +1dVerified
- Rhode Island State AGbd_a58e9e0b70ac44ec2025-06-17 · +1dVerified
Show 6 more filings ↓Show fewer ↑up to 15d gap
- California State AGbd_bbd9bb1e831f985e2025-06-17 · +1dCandidate
- New Hampshire State AGbd_53b697732f6e933e2025-06-18 · +2dVerified
- South Carolina State AGbd_a377bfb677b7e83f2025-06-18 · +2dVerified
- Texas State AGbd_b0dd709ac92a96cf2025-06-18 · +2dVerified by operator
- Maine State AGbd_fa81ee53b98afb242025-06-18 · +2dVerified by operator
- Illinois State AGbd_942423996e40aa312025-06-01 · +15dVerified
Filing propagation · 11 filings · 11 states
View merged incident ↗Pattern: first filing Jun 1 (IL), last Jun 18 (ME) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.