Krispy Kreme Doughnut Corporation
bd_f982d42904410829 · schema v1 · pii pii-v1
Full breach record for Krispy Kreme Doughnut Corporation →Krispy Kreme Doughnut Corporation notified Delaware AG of unauthorized activity on IT systems discovered Nov 29, 2024. Personal information was impacted; no evidence of misuse. Company engaged cybersecurity experts, contacted law enforcement, and offered Kroll identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 29, 2024
Discovered
Jun 16, 2025
Filed
vs. sector median
+21 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Indiana State AGbd_0d261f83a1177f1a2025-06-16Verified
- Vermont State AGbd_19e91671f3e66bc82025-06-16Verified
- Massachusetts State AGbd_65362ff1582efe022025-06-17 · +1dVerified
- Rhode Island State AGbd_a58e9e0b70ac44ec2025-06-17 · +1dVerified
Show 6 more filings ↓Show fewer ↑up to 15d gap
- California State AGbd_bbd9bb1e831f985e2025-06-17 · +1dCandidate
- New Hampshire State AGbd_53b697732f6e933e2025-06-18 · +2dVerified
- South Carolina State AGbd_a377bfb677b7e83f2025-06-18 · +2dVerified
- Texas State AGbd_b0dd709ac92a96cf2025-06-18 · +2dVerified by operator
- Maine State AGbd_fa81ee53b98afb242025-06-18 · +2dVerified by operator
- Illinois State AGbd_942423996e40aa312025-06-01 · +15dVerified
Filing propagation · 11 filings · 11 states
View merged incident ↗Pattern: first filing Jun 1 (IL), last Jun 18 (ME) — a 17-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.