Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Krispy Kreme

Krispy Kreme Vendor Cyber Rating & Cyber Score

krispykreme.com

Headquartered in Charlotte, N.C., Krispy Kreme is one of the most beloved and well-known sweet treat brands in the world. Our iconic Original Glazed® doughnut is universally recognized for its hot-off-the-line, melt-in-your-mouth experience. Krispy Kreme operates in more than 40 countries through its unique network of fresh doughnut shops, partnerships with leading retailers, and a rapidly growing digital business. Our purpose of touching and enhancing lives through the joy that is Krispy Kreme guides how we operate every day and is reflected in the love we have for our people, our communities, and the planet.


Krispy Kreme A.I CyberSecurity Scoring

Krispy Kreme
Company Information
Website:http://www.krispykreme.com
Employees number:10,305
Number of followers:131,591
NAICS:722
Industry Type:Food and Beverage Services
Homepage:krispykreme.com
Krispy Kreme Risk Score (AI oriented)
Between 0 and 549
logo
Krispy KremeFood and Beverage Services
Updated:
27/05/2026
350/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Krispy Kreme Global Score (TPRM)
xxxx
logo
Krispy KremeFood and Beverage Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Krispy Kreme
Krispy KremeCritical
Current Score
350C (CRITICAL)
01000
6 incidents
-105 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
367Before Incident
MAY 2026
455Before Incident
Breach
24 May 2026Krispy Kreme
Krispy Kreme: Krispy Kreme $1.6 million settlement can earn Floridians up to $3,500

Krispy Kreme Settles $1.6M Class-Action Over 2024 Data Breach

350After Incident
CRITICAL-105
KRI1779668812
Krispy Kreme Settles $1.6M Class-Action Over 2024 Data Breach Krispy Kreme has agreed to a $1.6 million settlement in a class-action lawsuit alleging the company failed to prevent a November 2024 data breach that exposed sensitive customer information. The breach reportedly compromised names, dates of birth, Social Security numbers, and financial account details. While Krispy Kreme denies any wrongdoing or liability, the settlement covers U.S. residents who received a breach notification. Eligible consumers must file a claim by June 22, 2026, to receive compensation. All class members can claim a $75 cash payment, though the final amount may vary based on the number of claims submitted. Those with documented losses such as fraud or identity theft may receive up to $3,500 in reimbursement with proper evidence. Consumers who do not file a claim will still receive one year of credit monitoring, with activation codes provided via postcard notices. Claims can be submitted online through the [Krispy Kreme settlement website](https://www.krispykremebreachsettlement.com) or mailed to the settlement administrator. The deadline to opt out or object to the settlement is June 6, 2026. Florida has 32 Krispy Kreme locations, with the highest concentration in Jacksonville (4) and Pensacola (2). Nationwide, California leads with 41 locations, while the U.S. has a total of 361 stores.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $1,600,000 (settlement amount)Data Compromised: Names, dates of birth, Social Security numbers, financial account detailsLegal Liabilities: Class-action lawsuit settlementIdentity Theft Risk: High (exposure of SSNs and financial account details)Payment Information Risk: High (financial account details exposed)
DATA BREACH
NamesDates of birthSocial Security numbersFinancial account detailsSensitivity Of Data: High (PII and financial data)Personally Identifiable Information: Yes
APRIL 2026
451Before Incident
MARCH 2026
440Before Incident
FEBRUARY 2026
436Before Incident
JANUARY 2026
429Before Incident
DECEMBER 2025
422Before Incident
NOVEMBER 2025
419Before Incident
OCTOBER 2025
413Before Incident
SEPTEMBER 2025
406Before Incident
AUGUST 2025
399Before Incident
JULY 2025
392Before Incident
JUNE 2025
483Before Incident
Ransomware
05 Jun 2025Krispy Kreme
Krispy Kreme: FBI Aware of 900 Organizations Hit by Play Ransomware

Play Ransomware Gang Activity

378After Incident
CRITICAL-105
KRI1768390561
Play Ransomware Gang Hits 900 Victims in Three-Year Spree, Governments Warn The Play ransomware gang, also known as Playcrypt, has compromised approximately 900 organizations since its emergence in June 2022, according to an updated advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Australian Cyber Security Centre (ACSC). The group employs double-extortion tactics, encrypting systems while also exfiltrating sensitive data to pressure victims into paying ransoms. Initially reported to have targeted around 300 victims by October 2023, Play has since escalated its operations, becoming one of the most active ransomware groups in 2024. The latest advisory, released in May 2025, highlights new tactics, techniques, and procedures (TTPs) observed in recent attacks, including the exploitation of three critical vulnerabilities in the SimpleHelp remote monitoring and management (RMM) software. Tracked as CVE-2024-57727, CVE-2024-57728, and CVE-2024-57726, these flaws can be chained to gain administrator privileges and execute arbitrary code, fully compromising vulnerable systems. Play’s operators evade detection by recompiling the ransomware for each attack, tailoring it to specific targets. Victims are contacted via unique email addresses (using @gmx.de or @web[.]de domains) or phone calls, with threat actors often routing extortion demands to publicly listed numbers, such as help desks or customer service lines. The advisory also warns of an ESXi variant of the ransomware, which shuts down virtual machines (VMs) and encrypts related files using randomly generated per-file keys. Like the Windows variant, the ESXi version is recompiled for each campaign and includes command-line flags for targeted encryption or debugging. The joint advisory underscores Play’s growing threat as the group continues to refine its methods and expand its victim count.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortion
IMPACT
Windows systemsESXi virtual machinesOperational Impact: Encryption of critical files and VMs, leading to operational disruption
DATA BREACH
Personally identifiable informationFinancial dataSensitivity Of Data: High
DECEMBER 2024
480Before Incident
Cyber Attack
30 Dec 2024Krispy Kreme
Krispy Kreme

Krispy Kreme Black Friday 2024 Cyberattack and Data Breach

453After Incident
CRITICAL-27
KRI5093650100125
On Black Friday 2024, Krispy Kreme detected unauthorized network activity, marking the start of a cyber-attack that crippled its online ordering system until December 30, 2024. The incident led to significant financial and operational disruptions, including lost digital sales revenue, cybersecurity advisory fees, and system restoration costs, all of which materially impacted the company’s financial condition. Months later, in May 2025, Krispy Kreme disclosed that nearly 62,000 individuals had their highly sensitive data stolen, including Social Security numbers, financial account details, passport numbers, and biometric data. The breach exploited potential holiday-season vulnerabilities, such as understaffed security teams and relaxed IT monitoring. The prolonged investigation and recovery underscored the attack’s severity, with long-term reputational and financial repercussions for the company.
INCIDENT DETAILS -
TYPE
cyberattackdata breachransomware (implied by disruption and data theft)
MOTIVATION
financial gaindata theft
IMPACT
Financial Loss: material impact (revenue loss from digital sales, cybersecurity expert fees, system restoration costs)Social Security numbersfinancial account informationpassport numbersbiometric datapersonally identifiable informationonline ordering systemDowntime: 31 days (November 29, 2024 – December 30, 2024)Operational Impact: online ordering system offline, extended investigation periodRevenue Loss: loss of digital sales during peak holiday seasonBrand Reputation Impact: high (public disclosure of sensitive data breach)Identity Theft Risk: high (SSNs, financial data, biometric data exposed)Payment Information Risk: high (financial account information compromised)
DATA BREACH
personally identifiable information (PII)financial databiometric datagovernment-issued IDs (SSNs, passports)Number Of Records Exposed: 62,000Sensitivity Of Data: highData Exfiltration: yesPersonally Identifiable Information: yes
NOVEMBER 2024
546Before Incident
Breach
01 Nov 2024Krispy Kreme
Krispy Kreme Doughnut Corporation

Krispy Kreme Data Security Incident

470After Incident
HIGH-76
KRI606061925
Krispy Kreme Doughnut Corporation experienced a significant data breach in late November 2024, affecting thousands of current and former employees, along with their family members. The breach exposed highly sensitive personal information, including Social Security numbers, financial account information, biometric data, and medical information. The company has since implemented additional security measures and is offering complimentary credit monitoring and identity protection services to those affected.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numbersdates of birthdriver’s license numbersfinancial account informationcredit and debit card details with security codespassport numbersusernames and passwords for financial accountsbiometric datamedical and health insurance informationU.S. military ID numbersimmigration-related documentationdigital signaturesemail credentialsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Social Security numbersdates of birthdriver’s license numbersfinancial account informationcredit and debit card details with security codespassport numbersusernames and passwords for financial accountsbiometric datamedical and health insurance informationU.S. military ID numbersimmigration-related documentationdigital signaturesemail credentialsNumber Of Records Exposed: ThousandsSensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2024
762Before Incident
Breach
01 Jan 2024Krispy Kreme
Krispy Kreme Inc.: Krispy Kreme $1.6 Million Data Breach Deal Gets First Court Nod

Krispy Kreme Settles $1.6M Class Action Over 2024 Employee Data Breach

501After Incident
HIGH-261
KRI1772821859
Krispy Kreme Settles $1.6M Class Action Over 2024 Employee Data Breach Krispy Kreme Inc. has agreed to pay $1.6 million to resolve a proposed class action lawsuit alleging the company failed to adequately protect the personal data of nearly 162,000 employees exposed in a 2024 breach. The settlement received preliminary approval from the U.S. District Court for the Western District of North Carolina. Under the terms of the deal, affected employees defined as class members may claim up to $3,500 in reimbursement for documented losses tied to the breach or opt for a $75 cash payment. The incident underscores the financial and reputational risks companies face when employee data is compromised due to insufficient security measures. The breach highlights ongoing vulnerabilities in corporate data protection, particularly for large employers handling sensitive workforce information. The settlement reflects a growing trend of legal and financial consequences for organizations following cybersecurity failures.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $1,600,000Data Compromised: Personal data of employeesBrand Reputation Impact: Reputational risksLegal Liabilities: Class action lawsuit
DATA BREACH
Type Of Data Compromised: Personal dataNumber Of Records Exposed: 162,000Sensitivity Of Data: High (employee data)Personally Identifiable Information: Yes
Breach
01 Jan 2024Krispy Kreme
Krispy Kreme: Krispy Kreme customers could get $3,500 in payouts after data breach

Krispy Kreme Data Breach Settlement

501After Incident
CRITICAL-261
KRI1779892471
Krispy Kreme Settles $1.6M Lawsuit After 2024 Data Breach Exposing Customer Financial Data Krispy Kreme has agreed to a $1.6 million settlement following a 2024 cyberattack that compromised customers’ sensitive data, including Social Security numbers and bank account details. The breach, which exposed names, dates of birth, and financial account information, led to a class-action lawsuit alleging inadequate data protection. Affected customers who suffered fraud or financial losses may qualify for payouts of up to $3,500, while those without direct losses could receive $75. The settlement also includes a year of free credit monitoring and identity theft protection. Claims must be submitted by June 22, with documentation required for fraud-related compensation. As part of the agreement, Krispy Kreme has committed to strengthening its cybersecurity measures, though the company denies any wrongdoing. The final approval hearing is set for July 6. The doughnut chain, founded in 1937 and headquartered in North Carolina, operates over 340 U.S. locations, including 41 in California. Customers were notified of the breach and settlement, with officials cautioning against submitting claims without meeting eligibility requirements. The incident follows a similar $7.4 million settlement by Trader Joe’s last month over exposed credit card data on receipts.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: $1.6 million settlementData Compromised: Names, dates of birth, Social Security numbers, bank account details, financial account informationBrand Reputation Impact: YesLegal Liabilities: Class-action lawsuitIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
Social Security numbersBank account detailsNamesDates of birthFinancial account informationSensitivity Of Data: HighPersonally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Krispy Kreme ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Krispy Kreme's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Krispy Kreme's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Krispy Kreme ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Krispy Kreme's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Krispy Kreme Cyber Scoring History | Rankiteo