Dodo Pizza, a Russian fast-food chain operating around 1,500 restaurants across 28 countries, confirmed that hackers breached its systems and gained access to customers' personal information, including names, addresses, email addresses, phone numbers, dates of birth and order details. The company said it does not store customer payment information and that payment data was therefore not compromised, that the attackers' access has been blocked, and that it has notified the Russian communications regulator Roskomnadzor. A group calling itself DataSuckers claimed responsibility on Telegram, asserting it had obtained records belonging to 68 million customers across multiple databases. The company's own statement confirms a breach and the categories of data but does not corroborate the claimed volume, and the 68 million figure rests on the attacker's claim alone. The chain's Russian business reported about $120 million in revenue this month. The case follows the standard extortion playbook now common in Russian-speaking criminal activity: take the database, claim a round number, and let the publicity pressure the victim into negotiating — which is why the claimed record count should be treated as a negotiating position rather than a measurement.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-09-30 |
| Source | The Record |
| Reliability | Tier 2 |