Skip to content

Security1 publisher2 min readPublished

DataSuckers prices a claimed 68 million Dodo Pizza records at $100,000

Dodo Pizza confirmed hackers accessed customer names, addresses, birth dates and order details, while the DataSuckers group claims 68 million records. How many of its customers across 28 countries are affected rests, for now, on the attackers' word.

The Watch · Security desk

Illustration accompanying DataSuckers prices a claimed 68 million Dodo Pizza records at $100,000

What happened

  • Dodo says the attackers have been locked out, an internal investigation is under way and Russian regulator Roskomnadzor has been notified.
  • The company says it does not store payment information, so card data was not part of what the attackers reached.
  • DataSuckers also claims to hold 15 years of Dodo order history, a claim that could not be independently verified.
  • The group, which claimed the attack on its Telegram channel, says it plans to publish some of the data.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Anyone who ordered from Dodo can be sent a fake delivery or refund message that quotes their own address, phone number, birth date and past orders.
  • constraint If Dodo's payment statement holds, card reissuance is unnecessary, and the harder problem is any service desk that still accepts a birth date and address as proof of identity.
  • precedent The group's Tez Tour playbook makes a published Dodo sample the likeliest next test of the 68 million claim.

DataSuckers works in public. The group calls itself financially motivated. It posts detailed accounts of its intrusions on Telegram and invites victims, journalists and law enforcement to ask it for comment or samples [14]. "Dodo is a good company. And the pizza there is really good. I'm not a Dodo hater or anything like that," an administrator of the channel said. "But Dodo had one seemingly minor vulnerability that ultimately led to a complete compromise." [15]

Earlier this month the group claimed an attack on Tez Tour, one of Russia's major tour operators, and defaced the company's website [16]. It said it spent about two weeks inside and took customer information [17]. A Tez Tour representative confirmed the website disruption but did not admit that any data was stolen [18]. DataSuckers then posted screenshots of folders it said belonged to Tez Tour, along with a sample of what it called the company's database [19]. It later claimed to have sold the data for $10,000, a claim that has not been independently verified [20].

The Dodo asking price of about $100,000 [13] is ten times the Tez Tour figure [1]. That makes two Russian consumer companies in one month, each followed by Telegram claims and a price. The pattern points to a group running a repeatable operation against customer databases [7][16].

Dodo did not say how many customers were affected [11]. The 68 million figure and its multi-country scope come from the group's own Telegram claims [8]. A seller setting a price has reason to inflate volume. Dodo's footprint of about 1,500 restaurants in 28 countries [6] fits a customer base spread across several countries, though it cannot confirm 68 million records. Until the company's internal investigation produces its own count [4], 68 million is the figure to size notification and fraud monitoring against [8].

What to watch

  • A customer count from Dodo's internal investigation to set against the attackers' 68 million.
  • Whether a published DataSuckers sample includes customers outside Russia, as the group's multi-country claim implies.
  • Any claim by the group that it has sold the Dodo database, and at what price against the $100,000 asking figure.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories