VYPR
breachPublished Sep 29, 2026· 1 source

Russian Pizza Chain Dodo Pizza Confirms Cyberattack, Customer Data Potentially Exposed

Dodo Pizza, a Russian fast-food chain with 1,500 locations, has confirmed a cyberattack that may have exposed customer names, addresses, and order details.

Popular Russian fast-food chain Dodo Pizza has confirmed that its systems were breached by hackers, potentially exposing the personal information of its customers. The company stated that the compromised data could include names, addresses, email addresses, phone numbers, dates of birth, and details of customer orders. Importantly, Dodo Pizza emphasized that it does not store payment information, and therefore, no financial data was compromised in the incident.

The company has taken steps to address the breach, stating that the attackers' access has been blocked and an internal investigation is currently underway. Dodo Pizza has also officially notified Russia's communications regulator, Roskomnadzor, about the incident. The chain operates a significant network of approximately 1,500 pizza restaurants spread across 28 countries, with its Russian operations alone reporting substantial revenue.

A hacking group identifying itself as DataSuckers has claimed responsibility for the attack via its Telegram channel. The group alleges it gained access to Dodo Pizza's databases and obtained records belonging to an estimated 68 million customers across multiple countries, along with 15 years of order history. However, these claims have not been independently verified, and Dodo Pizza has not disclosed the exact number of customers affected.

DataSuckers has indicated intentions to publish some of the stolen data and has also offered to sell the entire database for approximately $100,000. An administrator for the hacking group commented that while Dodo Pizza is a "good company" with "really good pizza," a "seemingly minor vulnerability" ultimately led to a "complete compromise" of their systems.

The DataSuckers group describes its motivations as primarily financial rather than political. They utilize their Telegram channel to publicize details of their intrusions and openly invite victims, journalists, and law enforcement to contact them for comment or to obtain samples of allegedly stolen information. This modus operandi was also observed in a previous incident where DataSuckers claimed responsibility for an attack on Tez Tour, a major Russian tour operator.

In the Tez Tour incident, DataSuckers claimed to have spent two weeks within the company's systems, stealing customer information. While Tez Tour confirmed its website was disrupted, it did not explicitly admit to data theft. DataSuckers subsequently released screenshots and database samples, later claiming to have sold the stolen data for $10,000, though these claims also remain unverified.

The Dodo Pizza breach highlights ongoing threats to the food service industry and the broader retail sector, where customer data is a valuable target for cybercriminals. The scale of the alleged data theft, if confirmed, could have significant implications for millions of customers and further damage the reputation of the company and the industry.

As investigations continue, Dodo Pizza faces the challenge of managing customer trust, complying with regulatory requirements, and mitigating the fallout from the data exposure. The incident also serves as a stark reminder for businesses of all sizes to maintain robust cybersecurity measures and to be prepared for potential breaches.

Synthesized by Vypr AI