Krispy Kreme reported that a cyberattack in November 2024 led to the theft of personal information belonging to 161,676 people. The company said the vast majority of those affected were employees, members of their families and former employees.
The Workforce, Not The Customers
Coverage of a retail breach assumes shoppers. Here the affected population is the people who work there, the people related to them, and the people who used to work there.
Employee records are the least considered category in this database. Staff cannot take their data elsewhere, did not agree to the arrangement in any meaningful sense, and appear in the reporting as a footnote to whatever commercial disruption occurred.
Family Members Had No Relationship At All
Relatives appear in these records through benefits enrolment — a spouse on a health plan, a child as a dependant. They never dealt with the company.
That is one step further removed than the supplier cases that dominate this file set. The affected person is not the customer of a customer; they are the family of an employee of the breached organisation.
Compiled from the company’s regulatory notifications and public reporting, listed below. No operation is named and no entry route was published. Corrections: corrections@forensicpost.com.