On 5 October 2026, a group calling itself Datasuckers (also styled DataSuckers or DATASUCKERS) took over the website and app of ATB, Ukraine's largest supermarket chain. It posted a ransom page demanding US$400,000 in cryptocurrency and threatened to leak data it says belongs to about 7.9 million customers. ATB has confirmed that its resources were attacked. It denies that any personal data was taken and says those systems do not store it. Only the attackers have reported the data theft. No outside party has verified it, and the group has not published a sample. The group's two recent campaigns, against Tez Tour and Dodo Pizza, followed a similar pattern: large claims that the victim disputed.
What Happened
Ukrainska Pravda and Mezha (both part of the UP media group), UNN and PRM reported that ATB's web properties were disrupted on the morning of 5 October. UNN first described the incident at 12:33 local time. The attackers posted a Russian-language message on the ATB site: "ATB, we have your data, hurry before it reaches zero." It came with a two-hour countdown and a demand for US$400,000 in Bitcoin or USDT. Ukrainska Pravda reports that the placeholder page appeared intermittently and that the timer first showed the wrong time. The group said it would publish everything it had if the ransom was not paid.
ATB press secretary Serhii Demchenko gave slightly different statements to different outlets:
- To RBC-Ukraine (quoted by Ukrainska Pravda and Mezha): "Indeed, hackers are attacking the company's resources. No personal data has been compromised because we do not store it on these resources. The attack poses no danger."
- To UNN: he described "an attempt to hack the company's resources" that "did not affect any personal data or any confidential information." He added that the resources were being restored.
By ATB's own account, an attack did happen. The company describes it as a disruption of public-facing resources, not a data breach. UNN later reported that the ransom message had disappeared and the site was working again with technical maintenance underway. Ukrainska Pravda's report called the platforms "currently experiencing disruptions." The two reports were probably written at different points on the same day.
Accounts differ. The attackers describe a large data theft. ATB describes a contained attack that left personal data untouched.
What Was Taken
Everything in this section comes from the attackers. Ukrainska Pravda and Mezha report that Datasuckers claims to hold:
- Customers: about 7.9 million records with names, phone numbers, email addresses, physical addresses and password hashes. UNN gives the figure as "nearly 8 million." All outlets cite the same claim. No independent count exists.
- Employees: 127,265 records with identification details.
- Suppliers: 50,300 records with tax and contact information.
ATB says personal data is not stored on the affected resources, which would make this claim false. The group published no data sample with the ATB ransom note. The attacker's figures and ATB's denial therefore cannot be checked against each other yet.
The group's record suggests caution in both directions. In the Tez Tour incident in September 2026, Datasuckers said it had destroyed 395.5 million records. vpnlab.io and RAEM.KZ, citing Habr, point out that the listed categories add up to only about 371 million. Tez Tour said its booking and ERP systems were unaffected. In the Dodo Pizza case, fbrk.kz reports that the group published a 1,000-profile sample to dispute the company's statement that no Kazakh customers were affected. The group's numbers have been inflated before, but it has also produced sample data when a victim pushed back. Even so, fbrk.kz notes that no one has independently confirmed where that Dodo Pizza data came from.
Why It Matters
- ATB's scale. ATB is Ukraine's largest grocery chain. A real leak of customer contact data plus password hashes would give attackers material for large-scale phishing and credential-stuffing in a country under wartime cyber pressure.
- The group's profile is unclear. Datasuckers has been called hacktivist, but its activity looks like extortion: ransom demands, countdown timers and threats to leak. Its victims in Ukraine, Belarus, Russia and Kazakhstan don't share a political theme. The ATB message was written in Russian, but that alone does not establish who the group is or what it wants. Defenders should treat the group as an extortion actor until its motives are clearer.
- The recurring pattern. In each case, the group defaces a public site, posts a large and precise-sounding record count, then sets a short deadline. A two-hour timer is meant to push the victim into a quick decision before it can investigate. Victims and journalists should treat the stated record counts as unverified until a sample is checked.
- A denial does not settle it. "We don't store personal data there" can be true of the web front end and still not cover backend systems that the site or app talks to. A loyalty app with 7.9 million users must keep account data somewhere. Whether those systems were reached is the open question.
The Attack Technique
No source describes how ATB's website or app was compromised. ATB has not released technical details, and Datasuckers has not publicly claimed an entry point for this incident.
The only technical detail on record for this group comes from the Tez Tour case. vpnlab.io reports that Datasuckers told Habr it got in through a file-upload service that let it plant a file the web server ran as PHP inside a Docker container. From there, according to the group, it reached the internal network, SVN repositories containing database passwords, and a Tomcat Manager instance. It also said it spent about two weeks inside before going public. No one outside the group has verified any of this, and nothing shows that the same method was used against ATB. It still points defenders toward likely weak spots: upload handlers, container escape and lateral movement, secrets in source control, and exposed admin consoles.
The visible ATB activity matches the group's earlier pattern: it took control of public web content and posted a ransom page. That shows it could change what the site served. Whether it got any deeper is unknown.
What Organizations Should Do
- Lock down file uploads and server-side execution. Validate uploads by content, store them outside the web root, and turn off script execution in upload directories. Check container images for interpreters and network access they don't need.
- Remove secrets from source control. Scan SVN and Git history for database credentials, rotate anything found, and move secrets into a vault with scoped, short-lived access.
- Restrict admin interfaces. Tomcat Manager, CMS admin panels and CI dashboards should never be reachable from the internet or from web-tier containers. Put them behind VPN or zero-trust access with MFA.
- Watch for defacement and unauthorized content changes. File-integrity monitoring and external checks on public pages can catch tampering in minutes. Make sure you can restore a known-good site quickly.
- Prepare a response for short-deadline extortion. Prepare a playbook that assumes the attacker's numbers are unverified. Ask for a sample, check it against your production data, and run any public statement past legal and the DPO before replying to a countdown.
- Brief customers before phishing starts. Whether or not data was taken, publicity about the claim invites lookalike phishing. Tell customers which channels you will and won't use, and encourage them to reset passwords where accounts exist.
Sources: Hackers attack ATB supermarket chain: data of 7.9 million clients a... | ATB has been hit by a cyberattack: a ransom demand of $400,000 for... | The ATO was attacked by hackers | TEZ TOUR Cyberattack: Examining DataSuckers’ Leak Claims RAEM | Tez Tour hack: 395m records 'destroyed', firm denies leak | DataSuckers refuted Dodo Pizza's claim that no Kazakhstani data was... | No personal data is stored on the resources — ATB commented on the... | ATB's website was attacked by hackers who allegedly stole the ...