Russian pizza chain Dodo Pizza, which operates roughly 1,500 locations, confirmed that attackers breached its IT systems and may have accessed customer names, contact details, dates of birth, and order information. The company said payment-card data was not affected because it does not retain customers’ payment information. It blocked the attackers’ access, launched an internal investigation, and notified Russia’s data-protection regulator, Roskomnadzor.
A group calling itself DataSuckers claimed responsibility, alleging it stole records belonging to 68 million customers and 15 years of order history. The group reportedly offered the purported database for sale and threatened a partial publication, stating a financial rather than political motive. Dodo Pizza has not confirmed the claimed volume, and the scope and authenticity of the allegedly stolen data remain independently unverified.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
The group calling itself DataSuckers claimed responsibility for accessing Dodo Pizza databases, alleging it stole records for 68 million customers and 15 years of order history. It offered the purported database for about $100,000 and threatened to publish some data; the scope and authenticity of these claims were not independently verified.
Dodo Pizza disclosed that hackers breached its IT systems and may have accessed customer names, addresses, email addresses, phone numbers, dates of birth, and order details. The company said payment information was unaffected because it does not store payment data; it blocked attacker access, opened an internal investigation, and notified Roskomnadzor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.