Skip to content

WK Kellogg

Disclosed Apr 4, 20251 year ago4,093 affectedConfirmed

Official notice

WK Kellogg employee data stolen in Cleo file transfer attacks

WK Kellogg said an unauthorized person accessed Cleo-hosted servers used to transfer employee files to HR vendors on December 7, 2024, exposing names and Social Security numbers; it learned of it on February 27, 2025.

What is known

People affected4,093 (as reported by the organization)
DisclosedApr 4, 2025
DiscoveredFeb 27, 2025
HappenedDec 7, 2024
AttackSupply chain
Data exposedNames, Social Security numbers, Employment
SectorManufacturing · US
StatusConfirmed
Part ofCleo (2024)

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INApr 4, 202521
ResearchtotalApr 7, 2025

Same campaign

History of this record
  • 2026-09-25 · source_type: press to official · backfill source
  • 2026-09-25 · source_url: https://www.bleepingcomputer.com/news/security/food-giant-wk-kellogg-discloses-data-breach-linked-to-clop-ransomware/ to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-2025.pdf · backfill source
  • 2026-09-25 · status: disclosed to confirmed · backfill source
  • 2026-09-25 · verified_by: empty to in-ag · backfill source
  • 2026-09-25 · verified: 0 to 1 · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 4093 · backfill source
  • 2026-09-25 · disclosed: 2025-04-07 to 2025-04-04 · backfill source
  • 2026-09-25 · occurred: empty to 2024-12-07 · backfill source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about WK Kellogg

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.