ATB cyberattack: DataSuckers claim data theft, retailer denies it

Ukraine’s largest grocery chain, ATB, confirmed on Monday that it suffered a cyberattack, according to The Record. A group calling itself DataSuckers posted an extortion demand on the retailer’s website and claims it stole customer data. ATB denies that customer data was compromised, and the hackers’ claims have not been independently verified.

What we know

  • Per The Record, the hackers posted an extortion demand on ATB’s website, with a countdown timer that was later removed.
  • DataSuckers claimed responsibility and demanded $400,000, threatening to publish data it says it took.
  • ATB took some online services offline for what it called technical maintenance, and the website was unavailable at the time of reporting.
  • ATB said the message on its site did not affect data security and that the website remains under its control.
  • After ATB’s statement, the group posted samples of the allegedly stolen data on its Telegram channel and said it would sell the database instead of leaking it in full.

Who is affected

ATB operates more than 1,300 stores and employs more than 60,000 people as of early 2026. The retailer has already suffered heavy losses from the war, with hundreds of stores destroyed and warehouses damaged.

DataSuckers claims to hold data on 7.9 million customers: names, phone numbers, email and physical addresses and password hashes. It also claims employee passport information and records of more than 11 million orders. All of this is a claim by the attackers. ATB has not confirmed any of it.

What has not been confirmed

  • Whether any customer or employee data was actually stolen. ATB says no; the group says yes.
  • The authenticity of the published samples and screenshots, and the scale of the alleged breach.
  • How the attackers got in, and whether the website message came from a compromise of the site itself. Neither has been disclosed.
  • The group’s location. It appears to communicate mainly in Russian, but where it operates is unclear.

About DataSuckers

The Record reports that the group describes itself as financially motivated rather than politically aligned and publishes accounts of its claimed intrusions on Telegram. It recently claimed attacks on Russian companies. In September it claimed Dodo Pizza, which later confirmed attackers may have accessed customer names, addresses, emails, phone numbers, dates of birth and order details. It also claimed Tez Tour, a Russian tour operator, which confirmed website disruption but not data theft.

Why this matters

Analysis, not new facts. The pattern here is a public extortion demand followed by data samples once the victim denies a breach. In the Dodo Pizza case the company later acknowledged possible access, so an early denial is not proof that nothing was taken. Until ATB publishes forensic findings, treat the claim as unresolved rather than false.

If password hashes were really taken, the risk to customers depends on how those hashes were stored, which has not been disclosed. Reused passwords are the main downstream danger.

What to do

For ATB customers:

  1. Change your ATB password, and change it anywhere else you reused it.
  2. Turn on multi-factor authentication where the service offers it.
  3. Be wary of calls, texts or emails that mention your orders or loyalty account, since phone numbers and addresses are among the claimed data.
  4. Watch for official updates from ATB rather than the attackers’ channels.

For security teams:

  1. If you do business with ATB, ask for written confirmation of scope and whether your shared data or credentials are involved.
  2. Check whether staff use corporate emails on ATB accounts and prompt password resets for any overlap.
  3. Watch for credential-stuffing spikes against your own login pages and for phishing that cites retail orders.
  4. Do not visit or download from the attackers’ Telegram channel on corporate systems. Samples may be unsafe to handle.

Sources