Skip to content
cisonews.net

Incident · 8-K Item 1.05

Krispy Kreme reports online ordering disruption from unauthorized IT activity

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Krispy Kreme disclosed on December 11, 2024 that it had been notified on November 29 of unauthorized activity on part of its IT systems, and that online ordering in parts of the United States was disrupted. Its shops stayed open for in-person orders and deliveries to retail partners continued.

Filing details

The filing described the business impact as material until recovery was complete.

Krispy Kreme went further than most filers on cost. It said lost digital sales, adviser fees and restoration costs were reasonably likely to materially affect its results and financial condition, while expecting insurance to offset part of that. It did not expect a long-term material effect.

Unknowns in the filing

Krispy Kreme does not say who notified it, what kind of attack occurred, or whether data was taken. No amendment is in the log.

Sources

  1. 2024-12-11 · AKrispy Kreme, Inc., Form 8-K (SEC EDGAR), published December 11, 2024

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.