ATB cyberattack: DataSuckers demand $400,000 ransom

ATB cyberattack: DataSuckers demand $400,000 ransom

ATB, Ukraine's largest grocery store chain, has confirmed it was hit by a cyberattack. The confirmation came on Monday, after hackers placed an extortion demand directly on the retailer's website.

A group calling itself DataSuckers has claimed responsibility. It is asking for $400,000 and says it will publish data it claims to have taken from millions of ATB customers if the company does not pay.

A countdown on the company's own website

The ransom demand appeared on ATB's website along with a countdown timer. The timer was later taken down, and the site was unavailable at the time the original report was published.

ATB says customer data was not compromised. The company temporarily took some of its online services offline and described this as technical maintenance.

"The temporary message displayed on the website did not affect the security of your data," ATB said. "The website remains fully under ATB's control, and all information is securely protected."

The hackers did not accept that account. After ATB issued its statement, DataSuckers posted samples of the allegedly stolen data on its Telegram channel. The group said it would not leak the full database. Instead, it plans to sell it "for a substantial amount."

What the hackers say they took

According to DataSuckers, the stolen data covers 7.9 million customers. The group says this includes:

  • names and phone numbers
  • email and physical addresses
  • password hashes
  • passport information belonging to employees
  • records of more than 11 million orders

The group shared screenshots to back up its claims. Neither the authenticity of the data nor the scale of the alleged breach could be independently verified.

ATB is a major employer in Ukraine. As of early 2026, it ran more than 1,300 stores and had more than 60,000 employees. The company has already suffered heavily from Russia's war in Ukraine, with hundreds of its stores destroyed and warehouses damaged.

Who is DataSuckers?

DataSuckers says it is financially motivated and not aligned with any political side. It uses Telegram to publish detailed write-ups of the intrusions it claims to have carried out. It also openly invites victims, journalists and law enforcement agencies to contact it, whether for comment or to request samples of allegedly stolen data.

The group's recent victims have mostly been large Russian businesses. In September, it claimed an attack on Dodo Pizza, a Russian fast-food chain with about 1,500 restaurants in 28 countries. Dodo later confirmed the breach and said attackers may have accessed customer names, addresses, email addresses, phone numbers, dates of birth and order details.

DataSuckers also claimed an attack on Tez Tour, a major Russian tour operator, and defaced its website. The hackers said they spent about two weeks inside the company's systems and stole customer information. Tez Tour confirmed its website had been disrupted but did not confirm any data theft.

The group appears to communicate mainly in Russian. Where its members are based is unclear.

Our Take

The ATB case shows a familiar pattern: a public claim, a ransom figure, then a dispute over what was actually taken. ATB says its data is safe. DataSuckers answered with screenshots and samples. Until someone independently checks the material, customers are left with two conflicting stories, and that uncertainty is itself a form of pressure on the company.

The Dodo Pizza case is worth keeping in mind here. There, DataSuckers made a claim and the company later confirmed that customer data may have been accessed. That does not prove the ATB claims are accurate, and the Tez Tour case shows the group's statements are not always confirmed. Still, it suggests the claims should not be dismissed out of hand.

The group's targets also stand out. Moving from Russian firms to Ukraine's biggest grocer fits with its description of itself as purely financially motivated. For defenders, this matters: a group that is not picking sides by politics may choose victims mainly by size and the value of their data.

ATB customers would be wise to watch for phishing attempts that use their names, addresses or order history, and to change passwords they reused elsewhere, since password hashes are among the data allegedly stolen. Extortion crews also tend to fall apart under police pressure, as the recent arrest of a suspected KillSec leader shows.

It is worth watching whether ATB publishes any findings from its investigation, whether the data turns up for sale, and whether DataSuckers shifts further toward Ukrainian targets.