United States
USA
Krispy Kreme detected unauthorized activity on 29/11/2024 affecting part of its IT environment. Shops remained open and partner deliveries continued, but online ordering was disrupted in parts of the United States, causing lost digital sales and a direct interruption to the company's e-commerce order-processing flow. The Play ransomware group later claimed responsibility, but Krispy Kreme did not establish ransomware as the confirmed mechanism in its initial filing.
Estimated severity
70 / 100
Source reliability
94 / 100
Approximate Date
29/11/2024
Targeted Company
KRISPY KREME
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Please rotate your phone