Important update: The deadline to file a cash claim in the Krispy Kreme data-security settlement passed on June 22, 2026. New claims are no longer being accepted, according to the official settlement website.
People who submitted valid claims on time could receive up to $3,500 from a $1,616,760 class-action settlement linked to a cybersecurity incident discovered by Krispy Kreme on November 29, 2024.
The settlement resolves allegations arising from unauthorized access to private information held by the doughnut company. Krispy Kreme denied wrongdoing, and the agreement does not represent a court finding that the company violated the law.
Who was included in the Krispy Kreme settlement?
The settlement class covers living United States residents who were sent a notice stating that their private information may have been affected by the incident.
Receiving an official notice was important because the settlement did not automatically cover every Krispy Kreme customer, employee or shareholder. People who never received a notice were advised to contact the settlement administrator if they believed they qualified.
The information involved included some combination of names, dates of birth, Social Security numbers and financial-account access information. Not every affected person necessarily had every category of information exposed.
How much could eligible claimants receive?
Class members who filed before the deadline could choose between two forms of cash compensation.
- Documented-loss payment: Up to $3,500 for losses connected to fraud or identity theft resulting from the incident.
- Alternative cash payment: An estimated $75 for eligible claimants who did not request reimbursement for documented losses.
Claimants seeking as much as $3,500 were required to provide reasonable supporting records. These could include receipts, account statements, emails, telephone records or other documents showing that the claimed loss was related to fraud or identity theft caused by the incident.
The $75 figure was an estimate rather than a guaranteed payment. Settlement payments may be increased or reduced proportionally depending on the number of valid claims, administrative expenses and the money remaining in the fund.
Credit monitoring was also included
Settlement class members were offered one year of credit monitoring. The official notice said this benefit did not require a cash claim, although recipients would need the activation code included with their notice.
People who did nothing would receive no cash payment but could still receive the credit-monitoring benefit. They would also remain bound by the settlement and give up certain rights to bring separate claims involving the same allegations.
Key settlement dates
- June 6, 2026: Deadline to object to or exclude yourself from the settlement.
- June 22, 2026: Deadline to submit or postmark a cash claim.
- July 6, 2026: Date listed for the final approval hearing.
Because the cash-claim deadline has passed, affected people should use the official Krispy Kreme Data Security Settlement website to check the case status, payment information and credit-monitoring instructions. The settlement administrator can also be contacted at 1-877-239-1879.
Why affected people should continue monitoring their accounts
Social Security numbers and financial-access information cannot always be replaced as easily as passwords. Criminals may retain stolen data and attempt to use it months or years after the original incident.
Anyone who received a breach notice should review bank and credit-card activity, remain cautious about unexpected requests for personal information and check credit reports for unfamiliar accounts. Messages demanding payment to release settlement money should be treated as suspicious.
The long-term risk created by exposed personal information has also been seen in the CRA data breach compensation case, which involved claims connected to compromised government accounts.
Consumers can find additional steps for protecting their personal information in the report on the Origin Energy customer data breach, including why suspicious messages and unexpected account activity should not be ignored.













