Ukraine's largest grocery chain ATB confirms cyberattack as extortionists demand $400,000
The DataSuckers group posted a ransom note on ATB's own website and claims to hold data on 7.9 million customers. ATB says customer data was not compromised.
At a glance
- ATB confirmed the cyberattack on 5 October after a ransom message with a countdown timer appeared on its website.
- DataSuckers demanded $400,000 and claims to have taken data on 7.9 million customers plus records of more than 11 million orders.
- ATB says the message did not affect the security of customer data and took some online services offline for maintenance.
- The group published sample screenshots on Telegram after ATB's denial and says it will sell the database rather than leak it.
ATB, Ukraine's largest grocery chain, confirmed on 5 October that it had been hit by a cyberattack after an extortion message appeared on its own website, The Record reported. The group calling itself DataSuckers demanded $400,000 and claims to be holding personal data on 7.9 million of the retailer's customers — a claim ATB disputes.
What happened
According to The Record, the ransom note was posted directly on ATB's website and included a countdown timer, which was later removed. The company took some of its online services offline, describing the step as temporary technical maintenance. ATB said the message shown on the site did not affect the security of customers' data and denied that customer information had been compromised.
DataSuckers responded to that denial by publishing sample screenshots of what it says is stolen material on Telegram, The Record reported. The group says it intends to sell the full database rather than publish it — a route that makes the data harder to track once it changes hands, and harder for victims to confirm their exposure.
Technical details
The Record reported that DataSuckers claims the stolen set covers customer names, phone numbers, email and physical addresses and password hashes, along with employee passport information and records of more than 11 million orders. None of these claims has been independently verified, and the attackers' own figures are the only source for the scale of the incident so far. Neither the initial access route nor the dwell time has been disclosed.
The Record described DataSuckers as a financially motivated group that has also claimed recent attacks against Dodo Pizza and Tez Tour, which places this incident in a run of extortion activity against consumer-facing brands rather than in the state-linked destructive campaigns that have dominated Ukraine's threat landscape.
Who is affected
ATB operates more than 1,300 stores and employs over 60,000 people, according to The Record, and the chain has already absorbed heavy losses during Russia's invasion, including hundreds of destroyed stores. A loyalty and e-commerce dataset of the size claimed would touch a large share of the Ukrainian population. The published figures remain the attackers' assertions, and ATB's public position is that customer data was not exposed.
What to do
Customers of large retail loyalty programmes should assume phone numbers and email addresses in such datasets can surface in phishing and voice-based fraud, and treat unexpected contact that references recent orders with suspicion. Where a password was reused between a retailer account and anything else, change it elsewhere first. For defenders, an attacker able to post a message on a company's public website has reached a level of access that warrants a full review of content management and hosting credentials, not just the customer database.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



