October 5, 2026

Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.

Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

Ukraine’s largest grocery store chain, ATB, confirmed Monday that it was hit by a cyberattack after hackers posted an extortion demand on its website.

The hacker group DataSuckers claimed responsibility for the attack and demanded $400,000, threatening to publish data it claimed to have stolen from millions of ATB customers. A countdown timer for the ransom demand appeared on the retailer’s website but was later removed. The website was unavailable at the time of writing.

ATB denied that customer data had been compromised. The company temporarily took some online services offline for what it described as technical maintenance.

“The temporary message displayed on the website did not affect the security of your data,” ATB said. “The website remains fully under ATB’s control, and all information is securely protected.”

In response to ATB’s statement, the hackers published samples of the allegedly stolen data on their Telegram channel. They said they would not leak the entire database but would instead sell it “for a substantial amount.”

The group claimed to have obtained data belonging to 7.9 million customers, including names, phone numbers, email and physical addresses, password hashes, as well as employees’ passport information and records of more than 11 million orders.

DataSuckers published screenshots of what it said was stolen information to support its claims. The authenticity of the data and the scale of the alleged breach could not be independently verified.

ATB operates more than 1,300 stores and employs more than 60,000 people as of early 2026. Russia’s war in Ukraine has caused significant damage to the company, with hundreds of stores destroyed and warehouses damaged.

The DataSuckers group describes itself as financially motivated rather than politically aligned and uses a Telegram channel to publish detailed accounts of the intrusions it claims to have carried out. The group openly invites victims, journalists and law enforcement agencies to contact it for comment or samples of allegedly stolen data.

The group recently claimed attacks against several large Russian businesses.

In September, DataSuckers claimed responsibility for an attack on Dodo Pizza, a Russian fast-food chain with about 1,500 restaurants in 28 countries. Dodo later confirmed that attackers may have accessed customer names, addresses, email addresses, phone numbers, dates of birth and order details.

DataSuckers also claimed responsibility for an attack on Tez Tour, a major Russian tour operator, and defaced its website. The hackers said they had spent about two weeks inside the company’s systems and stole customer information. Tez Tour confirmed that its website had been disrupted but did not confirm that data had been stolen.

The hackers appear to communicate primarily in Russian, but their location is unclear.

Originally published on The Record