Cyber & AI intelligence
Wasteland.
Briefs indexed2938
Issues30
Published Mondays07:30 CT
▣ Breach DODO-PIZZA-DATA 2026-09-30

Dodo Pizza: DataSuckers Breach Exposes Customer Personal Data

"Dodo Pizza, the Russian pizza chain, has confirmed that attackers got into its IT systems and may have accessed personal data belonging to some of its customers. The company made the announcement on its Telegram and…"

Dodo Pizza, the Russian pizza chain, has confirmed that attackers got into its IT systems and may have accessed personal data belonging to some of its customers. The company made the announcement on its Telegram and VKontakte channels after a hacking group calling itself DataSuckers claimed the attack in public. Dodo Pizza says customers' names, addresses, email addresses, phone numbers, dates of birth and order contents may have been exposed. It has notified the Russian communications regulator, Roskomnadzor, and has not said how many people are affected. DataSuckers claims it took 2 to 3 TB of data covering about 68 million customers and 15 years of order history. No one has independently verified those figures. Sources also give different sizes for the chain: about 1,500 restaurants in 28 countries (The Record), more than 1,527 pizzerias in Russia and 27 other countries (Meduza), and more than 1,300 pizzerias and coffee shops in 26 countries for parent company Dodo Brands (Pravda).

What Happened

Dodo Pizza's statement, which several outlets quoted word for word, said: "yesterday and today there was a cyberattack on our IT system." It also said the attackers' access has been blocked and an internal investigation is ongoing. Accounts of the timing differ a little:

According to Xakep.ru, DataSuckers first posted on its Telegram channel overnight into September 28, saying it was downloading a multi-terabyte database from "a popular fast-food delivery service." It named Dodo Pizza later. The Record reports that the group offered to sell the database for about $100,000 and said it planned to publish part of it.

As a defensive step, Dodo Pizza forced customers to log out of their accounts. It told users not to worry if they were signed out because it was "one of the measures to protect accounts."

The Russian outlet SecPost says DataSuckers has also claimed this month's breach of tour operator Tez Tour, where it alleged 395.5 million records were stolen and sold to a "probiv" lookup bot. According to SecPost, the hackers also pointed to an earlier breach limited to Dodo's Belarusian operation. In May, Pizza Star LLC, which runs Dodo Pizza in Belarus, admitted a leak of customer names, delivery addresses, phone numbers and registration dates.

What Was Taken

What the company confirmed: names, addresses, email addresses, phone numbers, dates of birth and order contents for "some" customers. Dodo Pizza says it does not store payment data, so card details were not compromised.

What the attackers claim (unverified):

These figures come only from DataSuckers and from Baza, a Telegram channel that Meduza describes as close to Russia's security services. Security Lab, as cited by RBC Life, stressed that the group's claims cannot be treated as the established scale of the leak. For comparison, SecPost notes that in April Dodo Brands reported about 9 million monthly app users across 26 countries. A 15-year pool of registered accounts could be much larger than the monthly active user count, but the gap is big enough to treat the 68 million figure with caution.

Kazakhstan-based outlets (Kapital.kz, Infohub.kz) note that Dodo has not said whether Kazakh customers are affected. The hackers claim they have data from every market.

Why It Matters

Even if the attackers' numbers are inflated, a database that links a verified phone number, home address, date of birth and years of order history to each person is ideal material for social engineering. The Kazakh security service Blue Screen warns that this data is enough for highly convincing phishing. Examples include "delivery problem" calls, fake refund offers, and requests for SMS verification codes that appear to come from Dodo.

DataSuckers' business model makes this worse. The group says it is financially rather than politically motivated. It sells datasets and, by SecPost's account, has fed stolen records to probiv bots, which are commercial lookup services widely used in Russia for doxxing and fraud. Records that go into these services tend to stay available for good.

The group also said Dodo was better defended than Tez Tour but was brought down by "one seemingly minor vulnerability." That is a common pattern: a mature security programme can still be undone by one exposed service or leaked credential that gives access to central customer databases.

The Attack Technique

Neither Dodo Pizza nor any independent researcher has disclosed how the attackers got in. What is known comes only from the attackers:

Until Dodo publishes findings from its investigation, treat all technical details as claims from the attackers.

What Organizations Should Do

  1. Watch for bulk data export. Set alerts for unusual query volumes and large outbound transfers from customer databases. A multi-terabyte export over a few hours should trigger an automatic response.
  2. Limit how far one weakness can reach. Separate customer databases from internet-facing application layers, and give each service least-privilege database credentials so that one exposed endpoint does not open up the whole data estate.
  3. Keep less historical personal data. Fifteen years of full order history attached to identifiable profiles is a liability. Archive, aggregate or pseudonymise old records.
  4. Plan session revocation in advance. Dodo's forced global logout was the right move. Make sure you can revoke all sessions and rotate tokens and API keys quickly as part of incident response.
  5. Warn customers about phishing early. When contact data is exposed, tell customers straight away how you will and won't contact them. For example, say that you never ask for SMS codes or card details.
  6. Monitor Telegram and dark-web channels. Groups like DataSuckers announce intrusions publicly, sometimes before the victim notices. Monitoring these channels can shorten the time it takes to detect a breach.

Sources: Russian pizza chain with 1,500 locations confirms cyberattack follo... | Dodo Pizza confirms cyberattack: data of 68 million customers at ri... | «Додо Пицца» сообщила о кибератаке. В Сеть попали имена и адреса кл... | Хакеры заявили о взломе «Додо-Пиццы»: были похищены до 3 ТБ данных | Додо Пицца сообщила о кибератаке и утечке данных - новости Kapital.kz | «Додо Пицца» пострадала от кибератаки. Хакеры утверждают, что похит... | Russian pizza restaurant chain confirms cyberattack: Hackers claim... | Russian pizza chain Dodo Pizza says hackers breached its systems an...