{"id":6590,"date":"2024-12-11T16:13:51","date_gmt":"2024-12-11T22:13:51","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/krispy-kreme-doughnut-delivery-cooked-cyberattack"},"modified":"2024-12-11T16:13:51","modified_gmt":"2024-12-11T22:13:51","slug":"krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/12\/11\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack\/","title":{"rendered":"Krispy Kreme Doughnut Delivery Gets Cooked in Cyberattack"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt14c3ba617c41541b\/675a08d8e1616ceb1427164f\/krispy_kreme_Matthew_Horwood_Alamy_Stock_Photo.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">US doughnut dealer Krispy Kreme suffered a cybersecurity incident that&#8217;s made a mess of online ordering but spared retail operations that continue to serve up sugar-coated confections nationwide.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A Securities and Exchange Commission filing from Krispy Kreme disclosed the company was subject to an &#8220;unauthorized activity on a portion of its information technology systems&#8221; in late November.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The Company, along with its external cybersecurity experts, continues to work diligently to respond to and mitigate the impact from the incident, including the restoration of online ordering, and has notified federal law enforcement,&#8221; the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1857154\/000185715424000123\/dnut-20241211.htm\">Krispy Kreme 8-K filing<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> explained. &#8220;As the investigation of the incident is ongoing, the full scope, nature, and impact of the incident are not yet known.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Krispy Kreme added that while the cybersecurity incident is likely to have a &#8220;material impact&#8221; on the business until it is able to recover, anticipated losses are likely to be offset by cyber insurance.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond operational impact, the statement did not indicate whether customer data was compromised. Paul Bischoff, consumer privacy advocate at Comparitech, recommended anyone who&#8217;s ordered doughnuts online through Krispy Kreme should expect they&#8217;ve been exposed.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Most attacks of this nature don&#8217;t just disrupt systems,&#8221; Bischoff added. &#8220;They also steal data. Companies typically take about six months to investigate breaches and find contact information for affected customers, give or take a few months.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Krispy Kreme Incident Recovery Continues\">Krispy Kreme Incident Recovery Continues<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As the company <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cybersecurity-critical-breaches-disasters\">recovers from the incident<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Ilia Sotnikov, security strategist at Netwrix, said the Krispy Kreme cybersecurity team likely worked quickly to avoid more widespread damage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;All their shops are open and all delivery commitments to retail and restaurant partners are fulfilled,&#8221; Sotnikov said in a statement. &#8220;This means that the team identified the intrusion and was ready to swiftly follow the incident response plan.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Beyond initial concerns about business continuity, the entire Krispy Kreme supply chain is potentially vulnerable to follow-on cyberattacks, according to Ryan Sherstobitoff, senior vice president of threat research and intelligence at Security Scorecard.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As one of the world&#8217;s largest doughnut companies with over 400 US locations, this breach raises concerns about not only operational disruptions amidst the holidays but also the potential exposure of sensitive data within Krispy Kreme and its supply chain,&#8221; Sherstobitoff noted, in a statement. &#8220;With the holiday season in full swing, retailers must remain vigilant. Cybercriminals are lurking, waiting to exploit any distraction.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/krispy-kreme-doughnut-delivery-cooked-cyberattack\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>US doughnut dealer Krispy Kreme suffered a cybersecurity incident that&#8217;s<\/p>\n","protected":false},"author":12,"featured_media":6591,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6590","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=2560%2C1663&ssl=1",2560,1663,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=300%2C195&ssl=1",300,195,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=640%2C416&ssl=1",640,416,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=640%2C416&ssl=1",640,416,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=1536%2C998&ssl=1",1536,998,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=2048%2C1330&ssl=1",2048,1330,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=1024%2C665&ssl=1",1024,665,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/krispy-kreme-doughnut-delivery-gets-cooked-in-cyberattack-scaled.jpg?fit=2560%2C1663&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6590","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6590"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6590\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6591"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}