// AI threat desk · 6 Oct 2026
Home/LEAK · Data Leaks
Data LeaksMediumATBCVSS not assigned

ATB confirms cyberattack after DataSuckers extortion demand

ATB confirmed on Oct 5 that it was hit by a cyberattack after DataSuckers demanded $400,000 and threatened to publish customer data, The Record said.

AI-generated image of security analysts reviewing a cyberattack investigation in a dim operations centre.
AI-generated image, not a photo of the event.
Key takeaways
  • ATB confirmed it was hit by a cyberattack after an extortion demand appeared on its website, The Record said.
  • DataSuckers demanded $400,000 and claimed to have data from 7.9 million customers, according to The Record.
  • The Record said the alleged breach’s authenticity and scale could not be independently verified.

ATB confirmed on Oct 5 that it was hit by a cyberattack after hackers posted an extortion demand on the website, The Record said.

DataSuckers claimed responsibility and demanded $400,000, threatening to publish data it claimed to have obtained from millions of ATB customers. The Record said the group claimed the data covered 7.9 million customers, employee passport information and more than 11 million orders.

ATB operates more than 1,300 stores and employs more than 60,000 people as of early 2026, according to The Record. ATB denied that customer data had been compromised and temporarily took some online services offline for what it described as technical maintenance.

On this page

DataSuckers posted samples after ATB denied a data compromise

A ransom countdown appeared on ATB’s website and was later removed. The website was unavailable when The Record wrote its report.

ATB said the temporary website message did not affect data security and that its website remained under ATB’s control with information securely protected.

After ATB’s statement, The Record said DataSuckers published samples of allegedly obtained data on Telegram and said it would sell the database rather than publish it entirely, “for a substantial amount.” The group also published screenshots of information it said was taken from the company.

DataSuckers has claimed attacks against other businesses

The Record said DataSuckers describes itself as financially motivated rather than politically aligned and uses Telegram to publish accounts of claimed intrusions. The group recently claimed attacks against several large Russian businesses.

In September, DataSuckers claimed responsibility for an attack on Dodo Pizza. Dodo later said attackers may have accessed customer names, addresses, email addresses, phone numbers, dates of birth and order details.

DataSuckers also claimed responsibility for an attack on Tez Tour and said it had spent about two weeks inside the company’s systems and obtained customer information. Tez Tour confirmed that its website was disrupted but did not confirm that data had been taken.

The hackers appear to communicate primarily in Russian, but their location is unclear, The Record said.

The authenticity of the data samples and the scale of the alleged breach could not be independently verified, The Record said.

FAQ

What happened to ATB?

The Record said ATB confirmed on Oct 5 that it was hit by a cyberattack after hackers posted an extortion demand on its website.

Who claimed the ATB attack?

DataSuckers claimed responsibility and demanded $400,000 while threatening to publish data it claimed to have obtained from ATB customers.

How many ATB customers may be affected?

DataSuckers claimed to have obtained data belonging to 7.9 million customers, along with employee passport information and records of more than 11 million orders. The Record said the claims could not be independently verified.

Was ATB customer data confirmed to be compromised?

No. ATB denied that customer data had been compromised, while The Record said the authenticity of the alleged data and the breach’s scale could not be independently verified.

What did ATB do after the attack?

ATB temporarily took some online services offline for technical maintenance and said its website remained under its control with information securely protected.

Sources

  1. Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data, The Record
  2. How Russia Is Targeting Ukraine’s Food Chain, From Factories to Store Shelves, UNITED24 Media
How we checked this story
ClaimSourceStatus
The Record said aTB confirmed on 5 October 2026 that it was hit by a cyberattack after hackers posted an extortion demand on its website.The RecordAttributed
DataSuckers claimed responsibility and demanded $400,000 while threatening to publish data it claimed to have stolen from millions of ATB customers.DataSuckers, via The RecordAttributed
A ransom countdown appeared on ATB’s website and was later removed, while the website was unavailable when The Record wrote its report.The RecordAttributed
ATB denied that customer data had been compromised and temporarily took some online services offline for technical maintenance.ATB, via The RecordAttributed
ATB said the temporary website message did not affect data security and that its website remained under its control with information securely protected.ATB, via The RecordAttributed
The Record said after ATB’s statement, DataSuckers published alleged stolen-data samples on Telegram and said it would sell the database instead of leaking it entirely.The RecordAttributed
DataSuckers claimed to have obtained data belonging to 7.9 million customers, employee passport information, and records of more than 11 million orders.The RecordAttributed
The Record said dataSuckers published screenshots of information it said was stolen, but the data’s authenticity and the alleged breach’s scale could not be independently verified.The RecordAttributed
The Record said aTB operates more than 1,300 stores and employs more than 60,000 people as of early 2026.The RecordAttributed
The Record said dataSuckers describes itself as financially motivated rather than politically aligned and uses Telegram to publish accounts of claimed intrusions.The RecordAttributed
The Record said dataSuckers recently claimed attacks against several large Russian businesses.The RecordAttributed
In September, DataSuckers claimed responsibility for an attack on Dodo Pizza, which later said attackers may have accessed customer and order information.DataSuckers, via The RecordAttributed
The Record said dataSuckers claimed responsibility for an attack on Tez Tour and said it spent about two weeks inside the company’s systems and stole customer information.The RecordAttributed
Tez Tour confirmed that its website was disrupted but did not confirm that data had been stolen.Tez Tour, via The RecordAttributed
The Record said the hackers appear to communicate primarily in Russian, but their location is unclear.The RecordAttributed
UNITED24 Media said aTB introduced temporary purchase limits of no more than six units or kilograms for several grocery, egg, and bulk-product categories in one transaction.UNITED24 MediaAttributed
UNITED24 Media said aTB attributed the purchase limits to fallout from Russian strikes and speculative buying by resellers.UNITED24 MediaAttributed
UNITED24 Media said aTB said the purchase restrictions were temporary and that it was working to keep shelves supplied.UNITED24 MediaAttributed

Could not verify

  • Whether ATB customer data was compromised is not established
  • Whether the alleged stolen data is authentic is not established
Explore with AI