Ukraine's ATB Grocery Chain Hit by DataSuckers Ransomware Attack
Ukraine's largest grocery chain, ATB, has confirmed a cyberattack by the DataSuckers group, which is threatening to leak millions of customer records unless a $400,000 ransom is paid.

Ukraine’s largest grocery store chain, ATB, confirmed on Monday that it fell victim to a cyberattack, with the hacker group DataSuckers claiming responsibility and demanding a $400,000 ransom. The attackers threatened to publish data they claim to have stolen from millions of ATB customers, initially displaying a countdown timer on the company's website, which was later removed.
ATB has denied that any customer data was compromised, stating that the temporary message on the website did not affect data security and that the site remains under ATB's control. The company temporarily took some online services offline, citing technical maintenance. However, in a direct challenge to ATB's statement, the hackers subsequently published samples of the allegedly stolen information on their Telegram channel, asserting they would sell the entire database rather than leak it publicly.
The DataSuckers group claims to have obtained sensitive information from 7.9 million customers, including names, phone numbers, email and physical addresses, and password hashes. Additionally, they allege to possess employees’ passport information and records of over 11 million orders. Screenshots of this purported stolen data were released by the hackers to substantiate their claims, though the authenticity and scale of the breach remain unverified independently.
ATB is a significant retailer in Ukraine, operating more than 1,300 stores and employing over 60,000 people. The ongoing war in Ukraine has already inflicted substantial damage on the company, with numerous stores and warehouses destroyed or damaged.
The DataSuckers group identifies itself as financially motivated rather than politically aligned. They utilize a Telegram channel to detail their intrusions and openly invite victims, journalists, and law enforcement to contact them for comment or data samples. The group has recently claimed responsibility for attacks against several large Russian businesses.
In September, DataSuckers claimed an attack on Dodo Pizza, a Russian fast-food chain with approximately 1,500 locations globally. Dodo Pizza later confirmed that customer data, including names, addresses, email addresses, phone numbers, dates of birth, and order details, may have been accessed. The group also claimed responsibility for an attack on Tez Tour, a major Russian tour operator, defacing its website and allegedly stealing customer information during a two-week system intrusion, though Tez Tour only confirmed website disruption.
While the hackers appear to communicate primarily in Russian, their exact geographical location is unclear. The group's recent activities suggest a pattern of targeting businesses, with a focus on data exfiltration and extortion, extending beyond Russian entities to international operations.
This incident highlights the persistent threat of ransomware attacks against critical infrastructure and retail sectors, particularly in regions affected by geopolitical conflict. The dual claims of data compromise by hackers and denial by the victim company underscore the challenges in verifying breach details and the importance of robust incident response and communication strategies.