Skip to content

Ukraine grocery giant ATB confirms breach; DataSuckers extorts

ATB, Ukraine's largest grocery chain, confirmed a cyberattack after DataSuckers posted a $400,000 extortion demand and claimed data on 7.9 million customers. ATB disputes any customer-data loss.

Published 3 min read

ATB, Ukraine's largest grocery chain — more than 1,300 stores and 60,000-plus employees — confirmed a cyberattack on October 5 after the extortion group DataSuckers planted a ransom note and a countdown timer on the company's own website. The group demands $400,000 and claims to hold data on 7.9 million customers. ATB disputes that any customer data was compromised. As reporting at The Record notes, there is no vendor security advisory here — the primary material is ATB's public statement and DataSuckers' own Telegram posts, so weigh each claim against its source.

What the attackers claim

DataSuckers says it exfiltrated records on 7.9 million customers — names, phone numbers, email and physical addresses, and password hashes — plus roughly 11 million order records. The group also claims employee passport data and supplier records with tax and contact details. DataSuckers has posted sample data to its Telegram channel; the authenticity of the samples is not independently verified, and the full figures are the attackers' claims, not confirmed counts.

What ATB says

ATB confirmed an incident but denies customer data was compromised, characterizing the website disruption as technical maintenance and saying its systems remain under its control. The two accounts are in direct conflict: the company says no data loss, the group says millions of records. Until an independent review or a regulator weighs in, treat both as unconfirmed positions rather than established fact.

Who DataSuckers is

DataSuckers describes itself as financially motivated, not politically aligned, and operates a Telegram channel where it publishes detailed write-ups of the intrusions it claims. The group communicates primarily in Russian and has previously claimed breaches of Russian businesses, including Dodo Pizza and Tez Tour — a target history that cuts against a simple "Russia-vs-Ukraine" reading of this incident.

Action checklist

  1. If you have an ATB account, assume the password may be exposed and rotate it; change the same password anywhere you reused it.
  2. Watch for Ukrainian-language phishing and SMS lures referencing ATB orders or loyalty accounts — the claimed dataset includes phone numbers and order history, ideal for targeted social engineering.
  3. Organizations partnered with ATB (suppliers, logistics) should review any shared credentials or integrations given the claimed supplier-record theft.

Context

Extortion crews increasingly skip file encryption entirely: no ransomware binary, just theft, a note on the victim's own site, and a countdown. The leverage is reputational and regulatory, not operational downtime. DataSuckers' mixed target list — Russian firms before, a Ukrainian one now — is a reminder that financially motivated groups follow data and payout, not flags, and that "who's behind it" says little about "what they'll do with the data."

Related stories