Dodo Pizza Breached: Customer Data Exposed in Attack Claimed by DataSuckers
The popular Russian fast-food chain, **Dodo Pizza**, has confirmed a security breach impacting customer personal information. A hacking group identifying themselves as **DataSuckers** has claimed responsibility, alleging access to databases containing records of millions of customers and offering to sell the stolen data.
Hackers have successfully breached the systems of **Dodo Pizza**, a prominent fast-food chain with a global footprint. The company announced on Monday that the incident resulted in unauthorized access to sensitive customer data.
### Compromised Information and Company Response
According to **Dodo Pizza**, the breach potentially exposed customers' names, addresses, email addresses, phone numbers, dates of birth, and order details. Crucially, the company emphasized that no payment information was stored on the compromised systems, thus ensuring payment data remained secure.
"The attackers' access has been blocked, and an internal investigation is ongoing," **Dodo Pizza** stated, confirming that the Russian communications regulator **Roskomnadzor** has been notified of the incident.
### DataSuckers Claims Responsibility
A hacking collective calling itself **DataSuckers** has publicly claimed responsibility for the attack. Via their Telegram channel, the group asserted they had gained access to **Dodo Pizza's** databases.
**DataSuckers** further claimed to have acquired records for an astonishing 68 million customers across multiple countries, alongside 15 years of order history. While these claims remain unverified by independent sources, and **Dodo Pizza** has not disclosed the total number of affected customers, the group has stated its intention to publish a portion of the data and is offering to sell the entire database for approximately $100,000.
### Hacker Motivation and Previous Incidents
Interestingly, an administrator for the **DataSuckers** Telegram channel expressed a nuanced perspective: "Dodo is a good company. And the pizza there is really good. Iβm not a Dodo hater or anything like that. But Dodo had one seemingly minor vulnerability that ultimately led to a complete compromise."
The group describes its motivations as primarily financial, rather than political. They are known for publishing detailed accounts of their intrusions on their Telegram channel and openly invite contact from victims, journalists, and law enforcement for comments or data samples.
Earlier this month, **DataSuckers** also claimed an attack on **Tez Tour**, a major Russian tour operator. That incident involved defacing the company's website and, according to the hackers, two weeks of persistence within **Tez Tour's** systems, culminating in the alleged theft of customer information. Although **Tez Tour** confirmed website disruption, they did not admit to data theft. **DataSuckers** subsequently published screenshots and data samples, later claiming to have sold the stolen **Tez Tour** data for $10,000.