Clustered 6 filings across 6 jurisdictions · filing window Jun 16, 2025 → Jun 18, 2025. View entity profile → Other incidents for this victim →
incident inc_405396600f784732 · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
PII · Identity (basic)
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
CA DE IN ME TX VT
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
Nov 19, 2024
When the intrusion reportedly occurred, per the linked filings
Nov 29, 2024
Reported by VERMONT AG, CALIFORNIA AG filings
May 22, 2025
Reported by TEXAS AG, MAINE AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Krispy Kreme Doughnut Corporation reported a data breach to the Indiana Attorney General. The breach occurred on 2024-11-19 and was reported on 2025-06-16. 4,810 Indiana residents were affected. 161,676 individuals affected in total.
Affected (this filing): 161,676
Krispy Kreme Doughnut Corporation notified Vermont consumers of a data security incident discovered on November 29, 2024. Unauthorized activity on IT systems led to the compromise of personal information. The company engaged cybersecurity experts and law enforcement, and is offering complimentary identity monitoring services through Kroll. No evidence of misuse was found as of the notification date.
Delaware Attorney General received a data-breach notification from Krispy Kreme Doughnut Corporation. The source document provided is a PDF attachment containing only page markers (pages 1-4) with no visible breach details, counts, or incident specifics.
Krispy Kreme Doughnut Corporation notified the California Attorney General of a data security incident. The company was notified of unauthorized activity on November 29, 2024, and determined on May 22, 2025, that certain personal information was impacted. The breach date listed on the state form is November 19, 2024. The company engaged cybersecurity experts and law enforcement, and is offering identity monitoring services. No specific data types or affected counts are detailed in the provided notice template.
Krispy Kreme Doughnut Corporation based in Charlotte, North Carolina, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-05-22 and reported on 2025-06-18. 6,948 Texas residents were affected. 161,676 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail.
Affected (this filing): 6,948
Krispy Kreme Doughnut Corporation experienced an external system breach (hacking) affecting its IT systems between November 19 and December 23, 2024. Unauthorized activity was first detected on November 29, 2024, but the impact to personal information was not confirmed until May 22, 2025. A total of 161,676 individuals were affected nationally, including 21 Maine residents. Kroll identity monitoring services (12 months) were offered to affected individuals.
Affected (this filing): 21