Threat intel
Dodo Pizza breach: what is confirmed and what is claimed
Dodo Pizza confirmed a cyberattack; DataSuckers claims 68 million customer records. What is known, the phishing risk, and checks for any firm holding order data.
Dodo Pizza, the Russian-founded delivery chain, confirmed on September 29 that it was hit by a cyberattack over the weekend of September 27 and 28. The company says the data at risk includes customer names, addresses, email addresses, phone numbers, dates of birth and order details. It says it does not store payment data, so card details were not exposed. It has blocked the attackers' access, started an internal investigation and notified Roskomnadzor, Russia's communications regulator.
A group calling itself DataSuckers claimed the attack on Telegram. It says it holds records on 68 million customers and 15 years of order history, and it is offering the database for about $100,000. Dodo Pizza has not confirmed that number or said how many people are affected, and no independent party has verified the data. The chain runs about 1,500 locations in 28 countries according to The Record, while Pravda.ru gives more than 1,300 pizzerias and coffee shops in 26 countries. If you have ordered from Dodo Pizza in any of those countries, plan as if your contact details and order history are in the set.
What the attackers say they took
DataSuckers' numbers are detailed enough to be checked once a sample is examined, which is part of how such groups try to look credible. According to its posts, reported by fbrk.kz and Xakep.ru, the set holds 65 million unique phone numbers, 53.1 million customers who placed at least one order, and between 860 and 870 million orders, about 744 million of them in Russia. That leaves roughly 15 million registered accounts that never bought anything.
The group says downloading the whole database, several terabytes, took about three hours. It threatens to publish part of the data and says it is after money. Neither Dodo Pizza nor any outside researcher has confirmed any of these figures. Xakep.ru notes the gap between the two accounts: the company speaks of partial customer data, the attackers of a full copy.
Sources also disagree on scope by country. Fbrk.kz reports that Dodo's support team said customer databases are kept separately per country and that Kazakh customers were not affected. Pravda.ru describes the leak as covering all regions, Kazakhstan included. Until Dodo publishes a breakdown, treat the country scope as open.
This is the group's second big claim in a month. The Record, fbrk.kz and Xakep.ru all report that DataSuckers claimed an attack on the Russian tour operator Tez Tour earlier in September.
How the data gets used
Neither Dodo Pizza nor the attackers have published technical details of how access was gained, so there is no confirmed flaw to patch here. What matters for customers is the shape of the data.
A delivery record ties a name and phone number to a home address, a date of birth and a list of what was ordered, when and for how much. That is enough for a fraudster to write an SMS or make a call that sounds like the restaurant: "Your order of two pepperoni pizzas on September 14 to this address was double charged, confirm your card to get the refund." Quoting a real order is what makes the victim trust the message. Dates of birth also help with account recovery at other services that still ask for one as a security question.
The company says card data was never in the set. A message claiming your card was exposed in this breach is therefore false, and a sign of phishing.
What customers should do
- Treat any call, SMS, messenger or email that mentions a Dodo order, refund, bonus points or prize as suspect, however accurate the details. Open the official app yourself to check.
- Never read out a one-time code sent by SMS. Delivery apps and banks use those codes to log in or confirm payments, and a caller who asks for one is trying to take over an account.
- If you reused your Dodo password elsewhere, change it on the other services. The company has not said whether password data was in the affected system.
- Where a bank or mobile operator lets you set a verbal password or port-out PIN, set one now. With a phone number, name and birth date, a fraudster has much of what a call-centre identity check asks for.
If your business holds order or loyalty data
Delivery, retail and loyalty databases tend to grow without anyone deciding they should. This case shows the result: a claimed 15 years of orders and millions of accounts that never placed one, all in reach of a single intrusion if the attackers are right.
When a group claims to have your data, work through it in this order:
- Get the sample the group has posted. Compare its column names, internal ID formats and the newest timestamp against production. A sample whose latest order matches the claimed attack window is strong evidence; one that ends years ago may be an older leak being resold.
- Search the sample for canary records, meaning test customers or seeded email addresses that exist in only one database or backup. A hit tells you which store the data came from.
- Check database audit logs and API gateway logs for the claimed window. Look for full-table
SELECTqueries on customer and order tables, unusually long query durations, export jobs and outbound transfers in the gigabytes from database or application hosts. - Rotate every credential that can read those tables: database users, service accounts, API keys, and tokens held by analytics and BI tools.
- Notify your regulator within your legal deadline, and tell customers which fields are at risk before phishing based on them starts.
Then look at your own stores before someone else does:
- How many years of order history sit in the live database? Archive or aggregate anything older than you need for accounting and support.
- Delete registered accounts that never ordered after a fixed period of inactivity.
- If a date of birth is only there for age checks or birthday promotions, store a verified-adult flag or the birth month instead.
- Check whether any single service account can read every customer in every country. Split access by region and role, so one stolen key does not expose the whole customer base.
- Set an alert on reads above a normal day's volume from any account, including reporting tools, which often have the broadest read access and the least monitoring.
Our security operations team watches for bulk reads and odd exports like these, and our attack surface management work finds the exposed databases and APIs that make them possible. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: The Record, Mallory, fbrk.kz, Pravda.ru, Xakep.ru, Shattered.