Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-06 · updated: 2026-10-06 · tags: [incident, retail] · confidence: medium · severity: critical · affected_sectors: [retail] · au_impact: false

Ukraine's largest grocery chain, ATB (more than 1,300 stores, over 60,000 employees), confirmed Monday that it was hit by a cyberattack after the hacker group DataSuckers posted an extortion demand on its website — a $400,000 demand backed by a countdown timer (later removed) and a threat to publish data it claims to hold on millions of customers. ATB denied that customer data had been compromised, saying it took some online services offline for "technical maintenance" and that its website "remains fully under ATB's control." In response, the attackers published samples on their Telegram channel and said they would sell — not leak — the database, claiming data on 7.9 million customers including names, phone numbers, email and physical addresses, password hashes, employees' passport information and records of more than 11 million orders; the authenticity and scale could not be independently verified. Why it matters: ATB confirmed the attack but denied data theft, leaving the extent of exposure contested — and the retailer's wartime context makes it a high-visibility test of how disruption to a national food retailer is compounded by extortion.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-10-06
Source The Record
Reliability Tier 2