Krispy Kreme Doughnut Corporation
ent_019dea393240e42090be6550364d8d31
Disclosures
6
State AG · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
161,676
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Krispy Kreme Doughnut Corporation
- Normalized
- krispy kreme doughnut— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DM6UTZHRNUEP25
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- krispykreme.com
Disclosure history (6)newest first
- ⭐Texas State AGas victim2025-06-18
Krispy Kreme Doughnut Corporation based in Charlotte, North Carolina, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-05-22 and reported on 2025-06-18. 6,948 Texas residents were affected. 161,676 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
- 🦞Maine State AGas victim2025-06-18
Krispy Kreme Doughnut Corporation experienced an external system breach (hacking) affecting its IT systems between November 19 and December 23, 2024. Unauthorized activity was first detected on November 29, 2024, but the impact to personal information was not confirmed until May 22, 2025. A total of 161,676 individuals were affected nationally, including 21 Maine residents. Kroll identity monitoring services (12 months) were offered to affected individuals.
- 🐻California State AGas victim2025-06-17
Krispy Kreme Doughnut Corporation notified the California Attorney General of a data security incident. The company was notified of unauthorized activity on November 29, 2024, and determined on May 22, 2025, that certain personal information was impacted. The breach date listed on the state form is November 19, 2024. The company engaged cybersecurity experts and law enforcement, and is offering identity monitoring services. No specific data types or affected counts are detailed in the provided notice template.
- 🏎️Indiana State AGas victim2025-06-16
Krispy Kreme Doughnut Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-19 and was reported on 2025-06-16. 4,810 Indiana residents were affected. 161,676 individuals affected in total.
- 🍁Vermont State AGas victim2025-06-16
Krispy Kreme Doughnut Corporation notified Vermont consumers of a data security incident discovered on November 29, 2024. Unauthorized activity on IT systems led to the compromise of personal information. The company engaged cybersecurity experts and law enforcement, and is offering complimentary identity monitoring services through Kroll. No evidence of misuse was found as of the notification date.
- 💎Delaware State AGas victim2025-06-16
Delaware Attorney General received a data-breach notification from Krispy Kreme Doughnut Corporation. The source document provided is a PDF attachment containing only page markers (pages 1-4) with no visible breach details, counts, or incident specifics.