- ATB confirmed it was hit by a cyberattack after an extortion demand appeared on its website, The Record said.
- DataSuckers demanded $400,000 and claimed to have data from 7.9 million customers, according to The Record.
- The Record said the alleged breach’s authenticity and scale could not be independently verified.
ATB confirmed on Oct 5 that it was hit by a cyberattack after hackers posted an extortion demand on the website, The Record said.
DataSuckers claimed responsibility and demanded $400,000, threatening to publish data it claimed to have obtained from millions of ATB customers. The Record said the group claimed the data covered 7.9 million customers, employee passport information and more than 11 million orders.
ATB operates more than 1,300 stores and employs more than 60,000 people as of early 2026, according to The Record. ATB denied that customer data had been compromised and temporarily took some online services offline for what it described as technical maintenance.
On this page
DataSuckers posted samples after ATB denied a data compromise
A ransom countdown appeared on ATB’s website and was later removed. The website was unavailable when The Record wrote its report.
ATB said the temporary website message did not affect data security and that its website remained under ATB’s control with information securely protected.
After ATB’s statement, The Record said DataSuckers published samples of allegedly obtained data on Telegram and said it would sell the database rather than publish it entirely, “for a substantial amount.” The group also published screenshots of information it said was taken from the company.
DataSuckers has claimed attacks against other businesses
The Record said DataSuckers describes itself as financially motivated rather than politically aligned and uses Telegram to publish accounts of claimed intrusions. The group recently claimed attacks against several large Russian businesses.
In September, DataSuckers claimed responsibility for an attack on Dodo Pizza. Dodo later said attackers may have accessed customer names, addresses, email addresses, phone numbers, dates of birth and order details.
DataSuckers also claimed responsibility for an attack on Tez Tour and said it had spent about two weeks inside the company’s systems and obtained customer information. Tez Tour confirmed that its website was disrupted but did not confirm that data had been taken.
The hackers appear to communicate primarily in Russian, but their location is unclear, The Record said.
The authenticity of the data samples and the scale of the alleged breach could not be independently verified, The Record said.
FAQ
What happened to ATB?
The Record said ATB confirmed on Oct 5 that it was hit by a cyberattack after hackers posted an extortion demand on its website.
Who claimed the ATB attack?
DataSuckers claimed responsibility and demanded $400,000 while threatening to publish data it claimed to have obtained from ATB customers.
How many ATB customers may be affected?
DataSuckers claimed to have obtained data belonging to 7.9 million customers, along with employee passport information and records of more than 11 million orders. The Record said the claims could not be independently verified.
Was ATB customer data confirmed to be compromised?
No. ATB denied that customer data had been compromised, while The Record said the authenticity of the alleged data and the breach’s scale could not be independently verified.
What did ATB do after the attack?
ATB temporarily took some online services offline for technical maintenance and said its website remained under its control with information securely protected.
Sources
How we checked this story
| Claim | Source | Status |
|---|---|---|
| The Record said aTB confirmed on 5 October 2026 that it was hit by a cyberattack after hackers posted an extortion demand on its website. | The Record | Attributed |
| DataSuckers claimed responsibility and demanded $400,000 while threatening to publish data it claimed to have stolen from millions of ATB customers. | DataSuckers, via The Record | Attributed |
| A ransom countdown appeared on ATB’s website and was later removed, while the website was unavailable when The Record wrote its report. | The Record | Attributed |
| ATB denied that customer data had been compromised and temporarily took some online services offline for technical maintenance. | ATB, via The Record | Attributed |
| ATB said the temporary website message did not affect data security and that its website remained under its control with information securely protected. | ATB, via The Record | Attributed |
| The Record said after ATB’s statement, DataSuckers published alleged stolen-data samples on Telegram and said it would sell the database instead of leaking it entirely. | The Record | Attributed |
| DataSuckers claimed to have obtained data belonging to 7.9 million customers, employee passport information, and records of more than 11 million orders. | The Record | Attributed |
| The Record said dataSuckers published screenshots of information it said was stolen, but the data’s authenticity and the alleged breach’s scale could not be independently verified. | The Record | Attributed |
| The Record said aTB operates more than 1,300 stores and employs more than 60,000 people as of early 2026. | The Record | Attributed |
| The Record said dataSuckers describes itself as financially motivated rather than politically aligned and uses Telegram to publish accounts of claimed intrusions. | The Record | Attributed |
| The Record said dataSuckers recently claimed attacks against several large Russian businesses. | The Record | Attributed |
| In September, DataSuckers claimed responsibility for an attack on Dodo Pizza, which later said attackers may have accessed customer and order information. | DataSuckers, via The Record | Attributed |
| The Record said dataSuckers claimed responsibility for an attack on Tez Tour and said it spent about two weeks inside the company’s systems and stole customer information. | The Record | Attributed |
| Tez Tour confirmed that its website was disrupted but did not confirm that data had been stolen. | Tez Tour, via The Record | Attributed |
| The Record said the hackers appear to communicate primarily in Russian, but their location is unclear. | The Record | Attributed |
| UNITED24 Media said aTB introduced temporary purchase limits of no more than six units or kilograms for several grocery, egg, and bulk-product categories in one transaction. | UNITED24 Media | Attributed |
| UNITED24 Media said aTB attributed the purchase limits to fallout from Russian strikes and speculative buying by resellers. | UNITED24 Media | Attributed |
| UNITED24 Media said aTB said the purchase restrictions were temporary and that it was working to keep shelves supplied. | UNITED24 Media | Attributed |
Could not verify
- Whether ATB customer data was compromised is not established
- Whether the alleged stolen data is authentic is not established



