A major Russian pizza restaurant chain fell victim to a cyberattack that exposed customer information, the company announced this week. Dodo Pizza disclosed that intruders gained access to names, addresses, email addresses, phone numbers, dates of birth and order details belonging to some of its clientele. The firm emphasized that it does not retain payment card information on its systems, meaning financial data remained secure.

In a statement, Dodo Pizza said, "The attackers' access has been blocked, and an internal investigation is ongoing," and noted that it had informed Roskomnadzor, Russia's communications regulator, of the breach.

The company runs approximately 1,500 pizza outlets in 28 nations worldwide. Its Russian operations generated roughly $120 million in revenue this month, according to figures shared on the company's website.

A hacking collective known as DataSuckers took credit for the intrusion via its Telegram channel. The group asserted that it had penetrated Dodo Pizza's database infrastructure and obtained records for 68 million customers from multiple regions, including 15 years of transaction history. Neither Dodo Pizza nor independent sources have verified these assertions, and the company has not disclosed how many users were actually compromised.

DataSuckers indicated it would release portions of the stolen information and requested approximately $100,000 for the complete database.

A spokesperson for the hacking group's Telegram channel remarked, "Dodo is a good company. And the pizza there is really good. I'm not a Dodo hater or anything like that. But Dodo had one seemingly minor vulnerability that ultimately led to a complete compromise."

DataSuckers characterizes itself as profit-driven rather than ideologically motivated. The group uses its Telegram presence to share detailed breakdowns of its breaches and actively encourages targets, media outlets and law enforcement to reach out for statements or samples of purportedly stolen data.

Earlier this month, the same hacking group claimed responsibility for compromising Tez Tour, a prominent Russian travel operator. DataSuckers stated it had spent roughly two weeks inside the company's infrastructure and exfiltrated customer records. Tez Tour confirmed its website experienced disruption but declined to acknowledge any data theft.

DataSuckers subsequently released screenshots of directories it attributed to Tez Tour and a specimen of what it characterized as the company's database. The group later asserted it sold the pilfered information to a buyer for $10,000. These claims remain unverified by independent sources.