On July 23, 2025, the Everest ransomware group published what it claims are internal files stolen from Crumbl, the popular cookie retailer with locations across the United States. The data exposure affects anyone who has ordered from Crumbl, created an account on its website or app, or whose contact information appears in the company’s internal records.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Crumbl
Get alerted the next time Crumbl files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Crumbl’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Everest posted the Crumbl materials to its leak site on July 23, 2025. The files are described as internal documents exfiltrated during a ransomware incident. Exact victim counts have not been disclosed, and the precise categories of data remain under review by security researchers. Available reporting describes the incident as a classic ransomware operation in which attackers first gain access, exfiltrate information, and then threaten to publish it unless a ransom is paid.
Industry trackers such as DoxxScan™ continuous monitoring have not yet incorporated this specific leak, which is typical for fresh ransomware publications. The absence of an official Crumbl statement at the time of publication leaves many customers uncertain about whether their specific records were taken.
Why This Matters for You and Your Family
When a company like Crumbl loses control of internal files, the information inside often includes names, email addresses, phone numbers, physical addresses, and order histories. Any of these details can be combined with data from previous breaches to build a more complete picture of your household. Credential leaks from one service frequently cascade into others because people reuse passwords across shopping, banking, and social accounts.