CSIDB logo
Incident

Dodo Pizza

Incident posture

Attack window
Sep 2026
Location
Russia
Status
Unknown
CIA posture
Available to members
Updated
2026-10-01 09:25

Linked entities

Victim
Dodo Pizza
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2026
Discovered
Undetermined
Disclosed
Sep 2026
Resolved
Pending

Summary

Dodo Pizza confirmed unauthorized access to its IT systems during a weekend intrusion, said the access was blocked, opened an internal investigation, and reported the incident to Roskomnadzor while noting that its delivery services continued operating normally. The company stated that potentially exposed data included customer names, delivery addresses, phone numbers, email addresses, dates of birth, and order details, but emphasized that payment card information was not stored on its servers. A hacker group calling itself DataSuckers claimed to have exfiltrated records of about 68 million customers, several terabytes of data, and 15 years of order history, though Dodo Pizza has not verified those figures and no independent confirmation exists.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Sept 27-28 2026, Dodo Pizza experienced unauthorized access to its IT systems, which the company confirmed on Sept 29 after detecting the intrusion, blocking it, opening internal investigation, and reporting to Roskomnadzor. The company stated that its Dodo Pizza and Drinkit delivery services continued to operate normally throughout and after the incident, with no disruption to order taking or payment processing. Dodo Pizza also confirmed that it does not store payment data on its own servers, so card information was not exposed. The company identified that potentially accessed personal data included customer names, delivery addresses, phone numbers, email addresses, dates of birth, and order details.

On Sept 27 a group identifying itself as DataSuckers posted on its Telegram channel claiming to have gained full access to Dodo Pizza's infrastructure, to have downloaded the entire database in roughly three hours, and to have obtained records tied to about 68 million customers, several terabytes of data, and 15 years of order history. Dodo Pizza has not verified these figures, and as of the article date no independent researcher has confirmed the scale of the alleged theft. The company’s statement limited the confirmed scope to the personal data fields listed above and emphasized that the intrusion was contained and investigated.

The incident prompted Dodo Pizza to notify Roskomnadzor, the Russian federal communications and data‑protection regulator, as required for a suspected personal‑data breach. No service outage or disruption to delivery operations was reported. The company indicated that it would continue its internal investigation and would provide further detail once the review concluded. The confirmed facts remain that unauthorized access occurred between Sept 27 and 28 2026, was blocked, that non‑payment personal data fields were potentially accessed, and that the company reported the incident to the appropriate regulator.

Sources

Sources available to members: 1 source.

CSIDB