Krispy Kreme Doughnut Corporation
bd_b0dd709ac92a96cf · schema v1 · pii pii-v1
Full breach record for Krispy Kreme Doughnut Corporation →Krispy Kreme Doughnut Corporation based in Charlotte, North Carolina, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-05-22 and reported on 2025-06-18. 6,948 Texas residents were affected. 161,676 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_fa81ee53b98afb24Maine State AGfiled 2025-06-18Verified by operator
- bd_bbd9bb1e831f985eCalifornia State AGfiled 2025-06-17(1d gap)Candidate
- bd_0d261f83a1177f1aIndiana State AGfiled 2025-06-16(2d gap)Verified
- bd_19e91671f3e66bc8Vermont State AGfiled 2025-06-16(2d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 2d gap
- bd_f982d42904410829Delaware State AGfiled 2025-06-16(2d gap)Verified
Source provenance
- Source URL
- https://oag.my.site.com/datasecuritybreachreport/apex/DataSecurityReportsPage#BR-0004366
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 18, 2025
- Raw hash
- 8ac6d26b4df0638ce30f54d4265630d452252a864aa1a7eb08183db018c05173
Reporting entity
- Name
- Krispy Kreme Doughnut Corporationnorm: krispy kreme doughnut
- Domain
- krispykreme.com
Victim entity
- Name
- Krispy Kreme Doughnut Corporationnorm: krispy kreme doughnut
- Domain
- krispykreme.com
- Industry
- Otherllm
Incident
- Discovered
- May 22, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 6,948
- Data types
- IDENTITY_GOVERNMENTPHIPII
- Attack vector
- Unknown
- Threat actor
- External
Compliance
- Time to disclose
- 27 days(27 days from discovery to filing)
- Compliance flags
- TX AG ≤30d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.