Krispy Kreme Doughnut Corporation
ent_019dea393240e42090be6550364d8d31
Disclosures
11
State AG · 11 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
161,676
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Krispy Kreme Doughnut Corporation
- Normalized
- krispy kreme doughnut— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DM6UTZHRNUEP25
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- krispykreme.com
Disclosure history (11)newest first
- New Hampshire State AGas victim2025-06-18
Krispy Kreme Doughnut Corporation notified the NH Attorney General of a data breach impacting 12 NH residents. Unauthorized activity was detected on Nov 29, 2024. Compromised data included names, DOBs, SSNs, and financial account info. Notifications sent June 16, 2025. Credit monitoring offered.
- South Carolina State AGas victim2025-06-18
Krispy Kreme Doughnut Corporation notified South Carolina residents of a data breach discovered on November 29, 2024. Unauthorized activity occurred on IT systems. On May 22, 2025, the company determined personal information was impacted. No evidence of misuse was found. The company engaged cybersecurity experts, contacted law enforcement, and offered Kroll identity monitoring services.
- Texas State AGas victim2025-06-18
Krispy Kreme Doughnut Corporation based in Charlotte, North Carolina, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-05-22 and reported on 2025-06-18. 6,948 Texas residents were affected. 161,676 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
- Maine State AGas victim2025-06-18
Krispy Kreme Doughnut Corporation reported an external system breach (hacking) occurring between November 19, 2024, and December 23, 2024. The incident was discovered on May 22, 2025, affecting 161,676 individuals nationwide, including 21 Maine residents. Personal information was compromised. Krispy Kreme engaged cybersecurity experts and law enforcement, and offered 12 months of identity monitoring services through Kroll.
- Massachusetts State AGas victim2025-06-17
Krispy Kreme Doughnut Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-06-17. 179 Massachusetts residents were affected.
- Rhode Island State AGas victim2025-06-17
Krispy Kreme Doughnut Corporation notified the Rhode Island Attorney General of a data breach affecting 125 state residents. Unauthorized activity was detected on November 29, 2024, impacting names, DOBs, SSNs, and financial account data. Notices were mailed June 16, 2025, offering one year of Kroll identity monitoring.
- California State AGas victim2025-06-17
Krispy Kreme Doughnut Corporation notified the California Attorney General of a data security incident. The company was notified of unauthorized activity on November 29, 2024, and determined on May 22, 2025, that certain personal information was impacted. The breach date listed on the state form is November 19, 2024. The company engaged cybersecurity experts and law enforcement, and is offering identity monitoring services. No specific data types or affected counts are detailed in the provided notice template.
- Indiana State AGas victim2025-06-16
Krispy Kreme Doughnut Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-19 and was reported on 2025-06-16. 4,810 Indiana residents were affected. 161,676 individuals affected in total.
- Vermont State AGas victim2025-06-16
Krispy Kreme Doughnut Corporation notified Vermont consumers of a data security incident discovered on November 29, 2024. Unauthorized activity on IT systems led to the compromise of personal information. The company engaged cybersecurity experts and law enforcement, and is offering complimentary identity monitoring services through Kroll. No evidence of misuse was found as of the notification date.
- Delaware State AGas victim2025-06-16
Krispy Kreme Doughnut Corporation notified Delaware AG of unauthorized activity on IT systems discovered Nov 29, 2024. Personal information was impacted; no evidence of misuse. Company engaged cybersecurity experts, contacted law enforcement, and offered Kroll identity monitoring.
- Illinois State AGas victim2025-06-01
KRISPY KREME DOUGHNUT CORPORATION filed a data-breach notice with the Illinois Attorney General in June 2025 (case 25-06-240). The register records the breach as discovered on November 29, 2024. Personal information types reported: drivers license, financial account number, medical information, ssn, username password. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.