Articles Tagged with vendor contracts

7E0DCD95-4E0B-48C5-8518-44DD2E8595CE-300x200A doughnut chain, a mortgage servicer, and a payroll processing company have almost nothing in common as businesses. Different industries, different customers, different sizes. But all three ended up in the same place over the past two years: paying millions of dollars to settle lawsuits after hackers got into systems holding ordinary personal information. If you think your business is too small, too unremarkable, or too far outside the tech world to end up in the same position, these three cases say otherwise.

Krispy Kreme: Employee Data, Not Just Customer Data

Krispy Kreme discovered a data breach in November 2024 that exposed the personal information of 161,676 current and former employees, including Social Security numbers, dates of birth, and financial account access details. The lawsuits that followed alleged the company failed to comply with basic data security obligations under the FTC Act and industry standards, and specifically claimed the sensitive information was never encrypted or redacted. Krispy Kreme agreed to pay roughly 1.6 million dollars to resolve the claims.

D5CD5B04-0609-4107-B18A-7A2E86931444-300x200For twenty years, “cybersecurity” meant one thing for most business owners: protect the network. Firewalls, endpoint protection, employee training on phishing emails. You knew what you were defending and you generally knew what your insurance covered if you failed.

That model is already out of date.

Attackers have shifted targets. Instead of only breaking into your servers, they are going after the AI tools your business now runs on: the chatbot on your website, the AI agent your vendor plugged into your CRM, the automated workflow that reads your inbox and drafts responses. And the legal and insurance world has not caught up to the speed of that shift, which means a lot of business owners are exposed in ways they do not know about yet.

Contact Information