Krispy Kreme, Lakeview Loan, Complete Payroll: Why Data Breach Liability Is Now Every Business’s Problem

7E0DCD95-4E0B-48C5-8518-44DD2E8595CE-300x200A doughnut chain, a mortgage servicer, and a payroll processing company have almost nothing in common as businesses. Different industries, different customers, different sizes. But all three ended up in the same place over the past two years: paying millions of dollars to settle lawsuits after hackers got into systems holding ordinary personal information. If you think your business is too small, too unremarkable, or too far outside the tech world to end up in the same position, these three cases say otherwise.

 

Krispy Kreme: Employee Data, Not Just Customer Data

Krispy Kreme discovered a data breach in November 2024 that exposed the personal information of 161,676 current and former employees, including Social Security numbers, dates of birth, and financial account access details. The lawsuits that followed alleged the company failed to comply with basic data security obligations under the FTC Act and industry standards, and specifically claimed the sensitive information was never encrypted or redacted. Krispy Kreme agreed to pay roughly 1.6 million dollars to resolve the claims.

Notice what wasn’t at issue here. This wasn’t about credit card numbers stolen from customers buying doughnuts. It was employee data, the exact kind of information sitting in the HR and payroll files of virtually every business with a staff, regardless of industry. If your business has employees, you are holding the same category of information that got Krispy Kreme sued.

 

Lakeview Loan Servicing: The Tail Is Longer Than You Think

Lakeview Loan Servicing, one of the largest mortgage servicers in the country, along with several affiliated companies, experienced unauthorized access to customer files back in October 2021. Names, Social Security numbers, addresses, and loan numbers were exposed. The lawsuits alleged violations spanning multiple state consumer protection statutes along with the FTC Act and the Gramm-Leach-Bliley Act. The companies agreed to pay 26 million dollars to resolve the litigation, with final court approval happening in 2026, nearly five years after the breach occurred.

That timeline matters. A data breach is not a problem that resolves in a news cycle. Litigation, settlement negotiation, and court approval can stretch on for years, meaning a breach your business experiences today could still be generating legal costs, discovery obligations, and reputational exposure half a decade from now.

 

Complete Payroll Solutions: The Vendor Risk Nobody Talks About

This is the case that should get the most attention from ordinary business owners, because it isn’t really about the company that got breached. Complete Payroll Solutions experienced a ransomware attack in March 2024 that exposed the personal information of nearly 377,000 people, including Social Security numbers, driver’s license numbers, financial information, and health insurance details. The claims against the company included negligence, breach of implied contract, invasion of privacy, and unjust enrichment. The settlement reached 2.6 million dollars.

Here is the part that matters for your business specifically. Complete Payroll Solutions is a payroll processor. The people affected were not its own employees. They were employees of other businesses, businesses that outsourced payroll processing the exact same way most companies in Chicago do. If you use a third party payroll vendor, an HR platform, or any outside service that touches your employees’ personal information, a breach at that vendor becomes a breach affecting your people, whether or not your own systems were ever touched.

 

What Connects All Three Cases

Strip away the industry differences and the same pattern shows up every time. A business held ordinary personal information, Social Security numbers, dates of birth, financial details, the exact data types sitting in payroll systems, HR files, and customer databases everywhere. Something happened, a hack, a ransomware attack, unauthorized access, and that data got out. Lawsuits followed alleging the same basic claims: negligence, failure to implement reasonable security measures, breach of implied contract, invasion of privacy. None of these are exotic legal theories reserved for major corporations. They apply just as easily to a business with twelve employees as to a company with twelve thousand.

 

What This Actually Means for Your Business

If you run a business in Illinois, a few things follow directly from these cases, whether or not you’ve ever thought of yourself as holding sensitive data.

  1. You almost certainly hold the exact category of information at issue in all three cases, through payroll records, HR files, and any customer database with names, addresses, or financial details attached.
  2. If you use a third party payroll processor or HR platform, and most businesses do, you have inherited vendor risk that a breach at that vendor becomes a problem for your business and your employees, regardless of the strength of your own internal systems.
  3. Whether data was encrypted or redacted is not just a technical detail. It became the specific factual basis for the negligence claims in the Krispy Kreme litigation, meaning courts are treating basic security hygiene as a real legal question, not an afterthought.
  4. Illinois has its own data breach notification law with specific timelines and requirements for notifying affected individuals. A breach at your business, or at a vendor holding your employees’ or customers’ data, can trigger obligations you need a plan for before it happens, not after.

 

The Bottom Line

None of these three companies set out to be careless. They ended up paying millions anyway, because holding personal data creates legal exposure regardless of how unremarkable the business itself might seem. If your business has employees, uses a payroll vendor, or keeps any customer information on file, and most do, you are already holding what these lawsuits were about. The businesses that come out ahead are the ones that treat this as a legal and contractual question now, reviewing vendor agreements and security practices before a breach forces the question, not the ones that assume it only happens to bigger companies.

About George Bellas

George Bellas is a business attorney at Bellas & Wachowski in Chicago, where he helps business owners understand their data security obligations and the liability exposure that comes with holding employee and customer information. From reviewing vendor contracts with payroll processors and HR platforms to preparing businesses for Illinois’ data breach notification requirements, George works with clients to close the gaps before a breach turns into a lawsuit. If your business hasn’t reviewed its data security exposure recently, schedule a consultation with George Bellas today at 800.825.9260 or visit bellas-wachowski.com.

Contact Information