Cyber News

Krispy Kreme Hacked, Attackers Gain Unauthorized Access to IT Systems

Krispy Kreme, the iconic doughnut chain, has become the latest victim of a cyberattack that has disrupted its online ordering system in parts of the United States.

The company first detected unauthorized activity on its IT systems on November 29, prompting immediate action to contain and investigate the breach.

While Krispy Kreme’s physical stores remain operational and deliveries to retail and restaurant partners are unaffected, online ordering—a significant revenue stream—has been partially disabled.

This disruption has caused frustration among customers who rely on digital platforms for convenience. “I couldn’t order my usual dozen for my family breakfast,” lamented Mary Carter, a loyal customer from Texas. “It’s more than just donuts; it’s part of our routine.”

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

In a regulatory filing, Krispy Kreme acknowledged that the incident is having a “material impact” on its business operations. Digital sales account for approximately 15.5% of the company’s revenue, making this outage particularly damaging during the busy holiday season.

Analysts estimate a potential 12% dip in online sales during this period, compounded by costs associated with cybersecurity experts and system restoration efforts.

The company has engaged leading cybersecurity professionals to investigate and remediate the attack while notifying federal law enforcement.

However, the full scope and nature of the breach remain unclear as the investigation continues. Notably, no customer payment data has been reported compromised at this stage.

Krispy Kreme has emphasized its commitment to swiftly resolving the issue. “We are working tirelessly to restore our systems and ensure our customers can once again enjoy seamless online ordering,” a company spokesperson stated.

The financial implications are expected to be significant but manageable in the long term. The company holds cybersecurity insurance to offset some costs related to recovery efforts.

Despite this, Krispy Kreme’s stock price fell by 2% following news of the breach, reflecting investor concerns over the immediate impact on operations.

This incident highlights growing vulnerabilities in digital infrastructures across industries. As Krispy Kreme works to recover, experts predict increased scrutiny of its cybersecurity measures moving forward.

For now, customers can still enjoy Krispy Kreme’s offerings through in-person purchases at its 400 U.S. locations or via deliveries to grocery stores and restaurant partners like McDonald’s.

However, restoring full digital functionality remains a top priority for the company as it seeks to rebuild customer trust during this challenging time.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

SecAI Debuts at RSA 2025, Redefining Threat Investigation with AI

By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…

2 hours ago

How Healthcare Providers Investigate And Prevent Cyber Attacks: Real-world Examples

According to IBM Security annual research, "Cost of a Data Breach Report 2024", an average…

3 hours ago

NVIDIA Riva Vulnerabilities Exposes Enable Authorized Access to Cloud Environments

A critical security flaw in NVIDIA's Riva framework, an AI-powered speech and translation service, has…

4 hours ago

CISA Adds Broadcom Brocade Fabric OS Vulnerability to Known Exploited Vulnerabilities Catalog

CISA officially added a significant security flaw affecting Broadcom’s Brocade Fabric OS to its authoritative…

4 hours ago

AirPlay Zero-Click RCE Vulnerability Enables Remote Device Takeover via Wi-Fi

A critical vulnerability in Apple’s AirPlay protocol, dubbed AirBorne, has exposed over 2.35 billion active…

4 hours ago

Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox – Technical Details Disclosed

A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to…

5 hours ago