Third Party Attack at Kellogg

December 29, 2025

INCIDENT

Battle Creek, Michigan, food manufacturing giant, WK Kellogg Co. discovered in late February that a vendor it uses for secure file transfers, Cleo, experienced a security incident.
In response, WK Kellogg after discovering the incident Feb. 27 and immediately began to investigate. It contacted Cleo, and the company informed WK Kellogg an unauthorized person gained access on December 7. The attacker got into the servers Cleo hosted and Kellogg used for transferring employee files to human resources service vendors.
Cleo is a technology vendor used by multiple companies for its secure file transfer application.

Incident Date

February 27, 2025

Estimated Cost

Unknown at this time

Type of Malware

No Malware identified

Threat Source

No threat source identified