Ransomware Group Steals Personal and Financial Data from Krispy Kreme

The Play ransomware group has announced that they were behind the recent cyberattack on Krispy Kreme, the well-known donut and coffee retail chain.

On November 29, Krispy Kreme reported that they were experiencing operational disruptions due to the cyberattack, with online ordering in the United States being affected. While the company did not confirm the use of file-encrypting ransomware in the attack, signs pointed to ransomware being involved.

This week, the Play ransomware group claimed to have stolen a variety of sensitive data from Krispy Kreme, including IDs, personal information, and financial and accounting details. The group is threatening to release this data publicly if a ransom is not paid by December 21.

The Play ransomware group, also known as Playcrypt, has been active since at least June 2022 and has targeted hundreds of victims in the Americas and Europe. By December 2023, they had claimed responsibility for roughly 400 intrusions.

As of now, Krispy Kreme has not publicly confirmed the theft of their data by the threat actor. SecurityWeek has reached out to the company for clarification and will update readers once they receive a response.

With cyberattacks becoming increasingly common, it’s essential for companies to prioritize their cybersecurity measures to protect their data and operations. Stay tuned for more updates on this developing story.