Dodo Pizza, the Russian-founded pizza delivery chain that operates across more than a dozen countries, confirmed on September 29, 2026 that its IT infrastructure was hit by a cyberattack over the weekend of September 27-28. The confirmation came after a hacker group calling itself DataSuckers posted claims on Telegram that it had broken into the company’s systems and walked away with records tied to roughly 68 million customers. Dodo Pizza has not verified that number, and as of this writing no outside researcher has independently confirmed it either.
What makes this incident worth tracking isn’t just the size of the alleged haul. It’s the gap between what a company says happened and what an attacker claims happened, playing out in real time, in public, on Telegram. That gap is where most of the actual news is, and it’s a pattern anyone who has followed ShinyHunters’ breach claims or the back-and-forth between ransomware crews and their alleged victims will recognize immediately.
What Dodo Pizza has confirmed so far
Dodo Pizza’s own statement is narrower than the headlines it triggered. The company confirmed unauthorized access to its IT systems during the September 27-28 window, said it blocked the intrusion, and said it opened an internal investigation. It also reported the incident to Roskomnadzor, Russia’s federal communications and data-protection regulator, which is the standard notification step for any company operating in Russia that suspects a breach involving personal data.
On the question of what data might have been exposed, Dodo Pizza pointed to a specific, bounded set: customer names, delivery addresses, phone numbers, email addresses, dates of birth, and order details. That’s a meaningful list for a company with tens of millions of customers, but it stops well short of the worst-case scenario for a retail breach. Dodo Pizza said explicitly that it does not store payment data on its own servers, so card numbers were not in scope even under the attacker’s own telling of events. The company’s statement, translated from Russian, was direct: “Платежные данные мы не храним — они в безопасности” (“We do not store payment data — they are safe”).
Operationally, the company said both its Dodo Pizza and Drinkit delivery services kept running normally through and after the incident. There was no reported outage, no delivery disruption, and no indication that order-taking or payment processing systems went down. That’s consistent with an attacker who got into back-office or customer-data systems rather than the live transaction pipeline, though Dodo Pizza has not published a technical breakdown of how access was gained.
The DataSuckers claim: 68 million records, 2-3 TB, three hours
The numbers driving most of the coverage come entirely from the attacker, not from Dodo Pizza. A group identifying itself as DataSuckers posted on its Telegram channel: “Мы, DataSuckers, атаковали IT-инфраструктуру «Додо Пиццы»” (“We, DataSuckers, attacked the IT infrastructure of Dodo Pizza”). The same post claims the group had already scraped the company’s entire database — “Скачка всей базы (несколько терабайт) заняла примерно 3 часа” (“Downloading the entire database, several terabytes, took about three hours”) — and asserts a timeline: “27 сентября мы уже находились в их инфраструктуре, получили полные права доступа ко всем базам данных” (“On September 27 we were already inside their infrastructure, and had obtained full access rights to all databases”). Those lines appear in the group’s public Telegram post.
From there, secondary reporting filled in the scale. The Record, a news outlet that covers ransomware and data-extortion incidents, wrote that the group claimed it obtained records belonging to 68 million customers across multiple countries, along with 15 years of order history, according to The Record’s coverage. A separate figure circulating in connection with the same alleged database put the number of customers who had placed at least one order at 53.1 million, though that number traces back to reporting on the hackers’ claims rather than to Dodo Pizza’s own disclosure.
None of the headline numbers, the 68 million figure, the 2-3 TB estimate, or the 15 years of history, have been confirmed by Dodo Pizza or by an independent forensic review. That distinction matters for anyone trying to size up their own exposure. A claim that a database was “scraped” or “downloaded” by an attacker is not the same as proof that the full dataset is intact, usable, and actually in the hands of a buyer. Extortion groups have a long track record of rounding up.
Timeline of the incident
| Date | Event | Source |
|---|---|---|
| Sept. 27, 2026 | DataSuckers claims initial access to Dodo Pizza’s infrastructure, per its own Telegram post | DataSuckers Telegram channel |
| Sept. 27-28, 2026 | Attack window Dodo Pizza cites in its official confirmation | Dodo Pizza statement |
| Sept. 28, 2026 | DataSuckers claims a roughly three-hour bulk download of “several terabytes” of data | DataSuckers Telegram channel |
| Sept. 29, 2026 | Dodo Pizza confirms unauthorized access, says it was blocked, reports incident to Roskomnadzor | Dodo Pizza statement, reported by english.pravda.ru |
| Sept. 29, 2026 | Meduza and other outlets report the company’s confirmation alongside the hackers’ 68-million-record claim | Meduza |
| Sept. 29-30, 2026 | Dark-web and breach-tracking outlets cover the alleged listing tied to the stolen data | Medianama |
Confirmed facts vs. unverified claims
Given how fast this story is moving, and how much of it rests on a hacker group’s own Telegram post, it’s worth laying out exactly what is established and what is not. Readers, and especially Dodo Pizza customers trying to decide whether to change a password, deserve that distinction spelled out plainly rather than blended into a single “68 million exposed” headline.
| Claim | Status | Attributed to |
|---|---|---|
| Cyberattack occurred Sept. 27-28, 2026 | Confirmed | Dodo Pizza |
| Unauthorized access was blocked; investigation opened | Confirmed | Dodo Pizza |
| Incident reported to Roskomnadzor | Confirmed | Dodo Pizza |
| Payment data not stored, not exposed | Confirmed | Dodo Pizza |
| Dodo Pizza and Drinkit services operating normally | Confirmed | Dodo Pizza |
| Names, addresses, phone numbers, emails, birth dates, order details potentially affected | Confirmed as potentially affected (scope, not count) | Dodo Pizza |
| 68 million customers affected | Unconfirmed | DataSuckers claim |
| 2-3 TB of data stolen | Unconfirmed | DataSuckers claim |
| 15 years of order history obtained | Unconfirmed | DataSuckers claim, cited by The Record |
| 53.1 million customers with at least one order in the dataset | Unconfirmed | Reporting on the alleged database |
| DataSuckers as the group responsible | Unconfirmed attribution | Self-claimed by DataSuckers |
Why a pizza chain is a high-value target
Food delivery companies sit on an unusually rich pile of personal data relative to how little security attention they tend to get. A pizza order isn’t just a transaction, it’s a home address tied to a phone number, an email, a name, and often a recurring pattern of when someone is and isn’t home. Stack years of that on top of a loyalty or delivery-app account and you have a dataset that’s more useful for phishing, SIM-swap social engineering, and physical-security risk than a typical e-commerce breach.
Dodo Pizza’s footprint adds a wrinkle. The chain was founded in Russia and has since franchised into a number of other markets, which is why a breach reported through Russian regulatory channels can still carry international exposure. It’s the same dynamic that made the Nexus breach’s 153 million exposed IDs a cross-border story rather than a single-country one, and it’s part of why security researchers increasingly treat consumer retail and delivery platforms as soft targets worth watching alongside healthcare and financial services.
How this compares to 2026’s other breach claims
2026 has not been short on large breach claims that outran their confirmation. The pattern is familiar by now: a group posts a number on Telegram or a leak forum, the number gets attached to every headline about the incident, and the company either stays quiet, disputes the figure, or confirms an incident without confirming the scale. Dodo Pizza’s situation fits squarely into that pattern.
| Incident | Claimed scale | Company confirmation |
|---|---|---|
| Dodo Pizza (Sept. 2026) | 68 million customers, per DataSuckers | Attack confirmed; customer count not confirmed |
| ShinyHunters FBI claim | 5,000 names, 2-3TB data claimed | See shattered.io coverage |
| IDScan.net breach | 153 million IDs claimed | See shattered.io coverage |
| Revolut Italy email breach | 147GB claimed by attackers | See shattered.io coverage |
| Gold Star Mortgage / BrainCipher | Ransomware claim, lawsuit filed 3 days after | See shattered.io coverage |
The common thread across all of these is that the attacker-supplied number is almost always the biggest number available, and it’s the one that travels fastest. Journalists and security teams that want to stay accurate have to report the claim as a claim, then wait for the slower, less dramatic process of forensic confirmation, class-action discovery, or regulatory disclosure to fill in the real figure. That process can take weeks or months.
What DataSuckers is (and isn’t) known for
DataSuckers is not one of the long-established ransomware brands like Clop or LockBit with years of leak-site history behind it. The group’s claim against Dodo Pizza rests entirely on its own Telegram channel, where it has published the access claims, the volume estimate, and the download timeline. There is no independent confirmation yet that the group actually possesses a complete, usable copy of Dodo Pizza’s customer database, as opposed to a partial sample or an exaggerated account of what it took.
That uncertainty cuts both ways. It means readers shouldn’t treat the 68-million figure as settled fact. It also means Dodo Pizza customers shouldn’t assume the opposite, that because the number is unconfirmed, there’s nothing to worry about. Dodo Pizza has already confirmed the attack happened and that a defined set of personal data fields was potentially accessible. That confirmation alone is enough reason for affected customers to be cautious about phishing attempts referencing their order history or delivery address.
Regulatory angle: what reporting to Roskomnadzor means
Roskomnadzor is Russia’s federal service for supervision of communications, information technology, and mass media, and it doubles as the country’s data-protection regulator for personal data incidents. A report to Roskomnadzor is a standard, required step for a Russian company that suspects a personal-data breach, similar in spirit to a GDPR breach notification in the EU or a state attorney general filing in parts of the US. It does not, on its own, tell the public how many people were affected or what enforcement action, if any, will follow.
What it does signal is that Dodo Pizza is treating the incident as a genuine personal-data exposure rather than a contained, low-impact intrusion. Companies generally don’t file with a data-protection regulator unless they believe personal data was, or plausibly could have been, accessed. That’s consistent with Dodo Pizza’s own public list of potentially affected fields.
What customers should actually do right now
Given what’s confirmed, and setting aside the unverified 68-million figure, Dodo Pizza customers face a fairly conventional exposure profile: contact information and order history, not payment data. The practical response looks the same as it does for most retail and delivery breaches.
- Watch for phishing emails or texts that reference specific past orders, delivery addresses, or account details, since that kind of personalization is a strong signal of a breach-fueled phishing campaign rather than a generic scam.
- Don’t reuse the password from a Dodo Pizza account anywhere else. If you do, change it on every site where it’s reused, not just on Dodo Pizza’s app.
- Be skeptical of any unsolicited contact claiming to be from Dodo Pizza asking for payment details, since the company has stated payment data was never stored on its servers to begin with.
- If you’re in a market where Dodo Pizza reported the incident to a local regulator, watch for an official notification rather than relying solely on news coverage of the hackers’ claims.
Market and brand impact
Dodo Pizza has built its brand in large part around transparency and a tech-forward operating model, including a franchise system that leans on a proprietary back-office platform. A breach confirmation, even a narrow one, cuts against that positioning more than it would for a chain with a more traditional, less tech-centric brand story. Franchise operators in the markets Dodo Pizza serves will be watching for whatever technical detail the company eventually releases, both to reassure customers and to satisfy franchise partners who share liability exposure under most delivery-chain franchise agreements.
There’s no indication yet of a stock-market or investor reaction tied specifically to this incident, and Dodo Pizza has not issued the kind of formal securities filing that accompanied, for example, the Astrana Health breach’s SEC disclosure in the US market. That’s a function of jurisdiction as much as severity: Russian and CIS-market companies don’t carry the same disclosure obligations as US-listed firms, so the regulatory trail here runs through Roskomnadzor rather than a public filing.
Historical context: breach disclosure has gotten faster, not more accurate
Five years ago, a breach like this might have taken weeks to surface publicly, usually only after a security researcher stumbled on a leaked database for sale. In 2026, the cycle is inverted: the attacker announces first, on their own channel, often within a day or two of the intrusion, and the company is forced to confirm or deny within a news cycle instead of a quarter. That speed cuts against accuracy. Companies rushing to respond to a Telegram post don’t always have a completed forensic review in hand, and attackers have every incentive to round their numbers up for maximum attention.
The UK’s own breach statistics show how common this has become at scale. National reporting has tracked cyber breach rates climbing across businesses of all sizes, a trend covered in shattered.io’s reporting on the UK’s 43% breach rate. Dodo Pizza’s incident is one data point in a much larger pattern of retail and consumer-facing companies becoming routine targets rather than occasional ones.
What to expect next
A handful of things typically happen in the days and weeks after a claim like this surfaces, based on how comparable incidents have unfolded this year.
Prediction 1: Dodo Pizza will likely publish additional detail, or face pressure to, once its internal investigation concludes, particularly if regulators in markets outside Russia request it.
Prediction 2: DataSuckers or a reseller will probably attempt to sell or leak a sample of the claimed data on a forum or Telegram channel to substantiate the 68-million claim, which would be the first real test of whether the figure holds up.
Prediction 3: Expect the confirmed customer count, if Dodo Pizza ever releases one, to land below the attacker’s claim, consistent with the pattern seen in most large extortion-driven breach claims this year.
Prediction 4: Phishing campaigns referencing Dodo Pizza orders are likely to appear within days in the markets where the company operates, regardless of whether the full 68-million dataset is real.
Prediction 5: Other Russia- and CIS-market consumer platforms should expect increased scrutiny of their own data-handling practices in the wake of this story, the same way one high-profile breach tends to trigger a wave of “are we exposed too” reviews across an entire sector.
The bigger pattern: attacker claims as unverified news
The Dodo Pizza story is a useful case study in how to read a breach headline critically. A company confirming “unauthorized access” is not the same as a company confirming “68 million records stolen.” The first is a fact. The second, in this case, is a claim made by the people who benefit most from it sounding as large and alarming as possible. Readers, journalists, and security teams all have a role in keeping those two things separate, and in updating the record as harder evidence, a leaked sample, a regulator’s findings, a confirmed customer count, eventually arrives.
For now, what’s solid is this: Dodo Pizza was attacked between September 27 and 28, 2026, unauthorized access was blocked, the company notified Roskomnadzor, and a defined set of non-payment personal data fields was potentially exposed. Everything past that, the 68 million figure, the 2-3 TB estimate, the 15 years of history, remains a claim from the people who made the attack, unverified by the company or by independent researchers as of September 30, 2026.
Frequently asked questions
Did Dodo Pizza confirm a data breach?
Yes. Dodo Pizza confirmed unauthorized access to its IT systems during an attack on September 27-28, 2026. The company said the access was blocked and that it opened an internal investigation.
Were 68 million Dodo Pizza customers really affected?
That figure comes from the hacker group DataSuckers, not from Dodo Pizza. It has not been independently confirmed. Dodo Pizza has not disclosed a specific number of affected customers.
Was payment or card data exposed?
Dodo Pizza said it does not store payment data on its own servers, so card information was not in scope for this incident, even under the attacker’s claims.
What personal data might have been exposed?
Dodo Pizza listed customer names, delivery addresses, phone numbers, email addresses, dates of birth, and order details as the categories of data that could potentially have been accessed.
Who is DataSuckers?
DataSuckers is the name of the group that claimed responsibility for the attack on its own Telegram channel. The group’s attribution and its claims about the scope of stolen data have not been independently verified.
Are Dodo Pizza and Drinkit still working normally?
Yes. Dodo Pizza said both its Dodo Pizza and Drinkit delivery services continued operating normally through and after the incident.
Did Dodo Pizza report the breach to regulators?
Yes. Dodo Pizza reported the incident to Roskomnadzor, Russia’s communications and data-protection regulator.
What should Dodo Pizza customers do now?
Watch for phishing messages referencing past orders or delivery details, avoid reusing your Dodo Pizza account password elsewhere, and treat any unsolicited request for payment information as suspicious, since the company has said it never stored payment data to begin with.




