Dodo Pizza
Incident posture
Linked entities
- Victim
- Dodo Pizza
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Dodo Pizza confirmed unauthorized access to its IT systems during a weekend intrusion, said the access was blocked, opened an internal investigation, and reported the incident to Roskomnadzor while noting that its delivery services continued operating normally. The company stated that potentially exposed data included customer names, delivery addresses, phone numbers, email addresses, dates of birth, and order details, but emphasized that payment card information was not stored on its servers. A hacker group calling itself DataSuckers claimed to have exfiltrated records of about 68 million customers, several terabytes of data, and 15 years of order history, though Dodo Pizza has not verified those figures and no independent confirmation exists.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Sept 27-28 2026, Dodo Pizza experienced unauthorized access to its IT systems, which the company confirmed on Sept 29 after detecting the intrusion, blocking it, opening internal investigation, and reporting to Roskomnadzor. The company stated that its Dodo Pizza and Drinkit delivery services continued to operate normally throughout and after the incident, with no disruption to order taking or payment processing. Dodo Pizza also confirmed that it does not store payment data on its own servers, so card information was not exposed. The company identified that potentially accessed personal data included customer names, delivery addresses, phone numbers, email addresses, dates of birth, and order details.
On Sept 27 a group identifying itself as DataSuckers posted on its Telegram channel claiming to have gained full access to Dodo Pizza's infrastructure, to have downloaded the entire database in roughly three hours, and to have obtained records tied to about 68 million customers, several terabytes of data, and 15 years of order history. Dodo Pizza has not verified these figures, and as of the article date no independent researcher has confirmed the scale of the alleged theft. The company’s statement limited the confirmed scope to the personal data fields listed above and emphasized that the intrusion was contained and investigated.
The incident prompted Dodo Pizza to notify Roskomnadzor, the Russian federal communications and data‑protection regulator, as required for a suspected personal‑data breach. No service outage or disruption to delivery operations was reported. The company indicated that it would continue its internal investigation and would provide further detail once the review concluded. The confirmed facts remain that unauthorized access occurred between Sept 27 and 28 2026, was blocked, that non‑payment personal data fields were potentially accessed, and that the company reported the incident to the appropriate regulator.
Sources
Sources available to members: 1 source.