Krispy Kreme breach, data theft claimed by Play ransomware gang

Teilen:

​The Play ransomware gang has claimed responsibility for a cyberattack that impacted the business operations of the U.S. doughnut chain Krispy Kreme in November.

Krispy Kreme disclosed the incident and subsequent disruptions to its online ordering system in an SEC filing submitted on December 11. The company detected unauthorized activity on some of its information technology systems on November 29.

After the attack, Krispy Kreme also took measures to contain and remediate the breach and hired external cybersecurity experts to investigate the attack’s impact and scope.

“We’re experiencing certain operational disruptions due to a cybersecurity incident, including with online ordering in parts of the United States,” Krispy Kreme said in a message on its official website.

“We know this is an inconvenience and are working diligently to resolve the issue. [..] We’ll have our online ordering up as soon as we can. Our fresh doughnuts are available in our shops as always!”

Krispy Kreme’s Q3 2024 financial results show that digital orders represent 15.5% of the company’s sales, contributing to its 3.5% organic revenue growth in Q3 2024.

The American multinational coffeehouse chain and doughnut company operates 1,521 shops and 15,800 points of access, four “Doughnut Factories” in the United States, and 37 others internationally. As of December 2023, it employed 22,800 people in 40 countries. Krispy Kreme also partners with McDonald’s to have its products sold in thousands of additional McDonald’s locations worldwide.

While the company has yet to share additional details about the attack and, when approached by BleepingComputer for comment, shared a statement similar to the one filed with the SEC, the Play ransomware gang has now claimed the November breach and says they also allegedly stole data from the company’s network.

Krispy Kreme entry on Play Ransomware leak site
Krispy Kreme entry on Play Ransomware leak site (BleepingComputer)

Play ransomware claims, without proof, that they collected and stole files containing “private and personal confidential data, client documents, budget, payroll, accounting, contracts, taxes, IDs, finance information,” and more. The attackers now say they’ll publish the data this Saturday, November 21.

The Play ransomware operation surfaced over two years ago, in June 2022, with initial victims seeking help through BleepingComputer’s forums. Play operators steal sensitive data from breached systems to use in double-extortion schemes, pressuring victims into paying ransoms to avoid having the stolen data leaked online.

Previous notable Play ransomware victims include car retailer giant Arnold Clark, cloud computing company Rackspace, the City of Oakland in California, Dallas County, the Belgian city of Antwerp, and, most recently, American semiconductor supplier Microchip Technology.

The FBI issued a joint advisory with CISA and the Australian Cyber Security Centre (ACSC) last December, warning that the Play ransomware operation had breached the networks of around 300 organizations worldwide as of October 2023.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:22 pm, Juni 19, 2025
Wetter-Symbol 26°C
L: 25° | H: 28°
klarer Himmel
Luftfeuchtigkeit: 53 %
Druck: 1024 mb
Wind: 15 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 3%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:42 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
25° | 28°°C 0 mm 0% 8 mph 56 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
15° | 27°°C 0 mm 0% 10 mph 75 % 1025 mb 0 mm/h
Sa. Juni 21 10:00 pm
Wetter-Symbol
18° | 32°°C 0 mm 0% 10 mph 60 % 1021 mb 0 mm/h
So. Juni 22 10:00 pm
Wetter-Symbol
19° | 26°°C 0.69 mm 69% 15 mph 76 % 1014 mb 0 mm/h
Mo. Juni 23 10:00 pm
Wetter-Symbol
16° | 23°°C 0.2 mm 20% 14 mph 78 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 24°°C 0 mm 0% 8 mph 56 % 1024 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 20°°C 0 mm 0% 7 mph 63 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 6 mph 75 % 1024 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 6 mph 65 % 1024 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
24° | 24°°C 0 mm 0% 8 mph 47 % 1024 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 9 mph 35 % 1023 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 10 mph 35 % 1023 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 9 mph 41 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,956.18
0.21%
Ethereum(ETH)
€2,184.42
0.29%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.89
1.13%
Solana(SOL)
€126.92
0.36%
USDC(USDC)
€0.87
0.02%
Dogecoin(DOGE)
€0.148330
1.67%
Shiba Inu(SHIB)
€0.000010
0.29%
Pepe(PEPE)
€0.000009
1.64%
Nach oben scrollen