Ransomware

Krispy Kreme cyberattack (Play ransomware)

πŸ“… 2024-11-29 🏒 Krispy Kreme (food/restaurant chain) 🦠 Play ransomware
Primary Source β†—

Incident Details

Krispy Kreme detected unauthorized IT activity 29 November 2024; disclosed via SEC 8-K 11 December 2024. Online ordering disrupted. Play ransomware gang claimed attack in December; after failed ransom negotiations, released 184 GB of data on dark web leak site 21 December 2024. 161,676 individuals notified of data theft including SSNs, driver’s licences, financial account numbers, credit/debit card numbers with CVVs, passport numbers, biometric data, health insurance information. FBI and CISA have rated Play as one of the most damaging ransomware gangs (900+ attacks).

Technical Details

Initial Attack Vector
unknown
Vendor / Product
Krispy Kreme (food/restaurant chain)
Malware Family
Play ransomware

Timeline

  1. 2024-11-29 Breach occurred
  2. 2024-12-11 Publicly disclosed
  3. 2025-01-01 Customers notified