Ukraine's largest grocery chain, ATB, has confirmed that it fell victim to a cyberattack orchestrated by the hacker group known as DataSuckers. The attackers posted an extortion demand on ATB's website, asking for $400,000 and threatening to release data they claimed was stolen from millions of ATB customers. Although a countdown timer for the ransom demand appeared on the website, it was later removed, and the site was not accessible at the time of reporting.
ATB has denied any compromise of its customer data, asserting that some online services were taken offline temporarily due to technical maintenance. The company reassured its customers that the website remained under its control and that all information was securely protected. Despite this statement, DataSuckers released samples of what they claimed to be stolen data on their Telegram channel, threatening to sell the entire database for a large sum.
The hackers alleged that they obtained data from 7.9 million customers, including sensitive information such as names, phone numbers, email addresses, physical addresses, and password hashes. They also claimed to possess employee passport information and records of over 11 million orders. The authenticity and scope of this breach have not been independently verified.
ATB, which operates over 1,300 stores and employs more than 60,000 people, has already suffered significant losses due to the ongoing war in Ukraine, with many stores and warehouses damaged. DataSuckers, which describes itself as financially motivated, has previously targeted several large businesses in Russia, including Dodo Pizza and Tez Tour, claiming to have accessed sensitive customer data. The group communicates mainly in Russian, although their exact location remains unknown.

