Dodo Pizza data breach confirmed after DataSuckers claims

Dodo Pizza data breach confirmed after DataSuckers claims

Dodo Pizza, a Russian fast-food chain with around 1,500 restaurants, has confirmed that attackers got into its systems and may have accessed customers' personal information. The company made the disclosure on Monday, after a hacking group called DataSuckers publicly claimed the attack.

Dodo Pizza operates in 28 countries. According to figures on the company's website, its Russian business reported about $120 million in revenue this month.

What the company says was exposed

The chain said the potentially compromised data includes customers' names, home addresses, email addresses, phone numbers, dates of birth and order details.

Payment data was not affected, the company said, because it does not store customers' payment information.

"The attackers' access has been blocked, and an internal investigation is ongoing," Dodo Pizza said.

The company also reported the incident to Roskomnadzor, Russia's federal regulator for communications, IT and mass media. Roskomnadzor also oversees personal data protection in the country.

Dodo Pizza did not say how many customers were affected.

Hackers claim 68 million records

DataSuckers claimed the attack on its Telegram channel and said it had gained access to Dodo Pizza's databases.

The group says it took records belonging to 68 million customers in several countries, along with 15 years of order history. These figures could not be independently verified, and the company has not confirmed them.

The hackers said they plan to publish part of the data. They also offered to sell the full database for about $100,000.

An administrator of the group's Telegram channel said the breach started with a small weakness.

"Dodo is a good company. And the pizza there is really good. I'm not a Dodo hater or anything like that," the administrator said. "But Dodo had one seemingly minor vulnerability that ultimately led to a complete compromise."

The group did not say publicly what the vulnerability was, and Dodo Pizza has not said how the attackers got in.

A group that courts publicity

DataSuckers says its motives are financial, not political. That matters in the current climate, where many attacks on Russian companies are carried out by hacktivists tied to the war in Ukraine.

The group uses its Telegram channel to post detailed accounts of its intrusions. It also openly invites victims, journalists and law enforcement agencies to contact it for comment or for samples of the data it says it has stolen.

This approach resembles other extortion crews that trade in stolen customer databases and use public channels to pressure victims. Some of those crews have drawn heavy law enforcement attention, as seen in the recent FBI push against ShinyHunters members.

Tez Tour attack earlier this month

Dodo Pizza is not the group's first claimed victim this month. DataSuckers earlier said it attacked Tez Tour, one of Russia's major tour operators, and defaced the company's website.

The hackers said they spent about two weeks inside Tez Tour's systems and stole customer information. A company representative confirmed that the website had been disrupted but did not admit that any data had been stolen.

DataSuckers later posted screenshots of folders it said came from Tez Tour, along with a sample of what it described as the company's database. The group then claimed it sold the stolen data to a buyer for $10,000. None of these claims have been independently verified.

Why It Matters

The Dodo Pizza case shows how much sensitive data sits inside everyday consumer services. The chain says no payment data was involved, but names, addresses, phone numbers and dates of birth are still useful to criminals. Combined with order history, they could support convincing phishing messages or identity fraud. Anyone who has ordered from Dodo Pizza should watch for unexpected calls and emails that refer to past orders.

The gap between the company's statement and the hackers' claims is also worth noting. Dodo Pizza has not given a number of affected customers, while DataSuckers speaks of 68 million records. Until the investigation reports back, the real scale is unclear. This is a familiar pattern in breaches such as the recent Arizona court system incident, where the first disclosures leave important details open.

Two things are worth watching next: whether DataSuckers follows through on publishing samples, and whether Roskomnadzor takes any action. The group's quick move from Tez Tour to Dodo Pizza suggests it may keep targeting Russian consumer brands.