LiMP VPN
← All news

Dodo Pizza Hacked: Customer Data Exposed in Russia

Dodo Pizza Hacked: Customer Data Exposed in Russia

In short: On September 27–28, 2026, Dodo Pizza's Russian IT systems were hit by a cyberattack. Customer names, delivery addresses, phone numbers, emails, dates of birth, and order contents for part of the customer base were potentially exposed; the company does not store payment data, so card details were not affected. The DATASUCKERS group claims to have stolen 2–3 TB of data, though that volume is not independently confirmed yet. The company blocked further access, is investigating internally, and notified Russia's data protection regulator, Roskomnadzor.

If you've ever ordered through Dodo Pizza's app or website, it's worth checking whether your data has already surfaced in known public breach databases — that gives you a more concrete risk picture than relying on either side's public statements.

What happened on September 27–28

According to the company, the attack on Dodo Pizza's Russian IT infrastructure lasted two days — September 27 and 28, 2026. Security staff detected unauthorized access to internal systems and blocked the attackers' further movement. The company publicly confirmed the incident and notified Roskomnadzor, as required under Russia's personal-data-breach reporting rules.

What data is at risk

Per the company's disclosure, the following may have been exposed: customer names, delivery addresses, phone numbers, email addresses, dates of birth, and the contents of past orders. Dodo Pizza emphasized that it does not store customer payment data on its own systems — payments run through third-party processors — so card numbers and transaction details were not part of the attack surface.

Even without banking details, this combination is enough to fuel targeted phishing and social engineering: an attacker who already knows your name, address, and order history can convincingly impersonate support staff, a courier, or your bank.

What the attackers claim

The DATASUCKERS group — the same group that earlier claimed responsibility for breaching tour operator Tez Tour — took credit for the attack. It claims to have exfiltrated 2 to 3 terabytes of data from Dodo Pizza's systems. That figure has not been independently verified by security researchers or confirmed by the company, which is typical for this kind of incident, where an attacker's initial claims often outpace what the victim organization can confirm.

What this means for customers

While the investigation is ongoing, the safer approach is to assume the worst rather than wait for an official confirmation of the leak's full scope. If you've ordered from Dodo Pizza, watch for:

  • Unexpected calls or messages claiming to be from Dodo support, your bank, or a courier service, asking you to confirm card details, share an SMS code, or click a link — a classic smishing pattern after a contact-data leak, covered in our guide on recognizing and defending against smishing.
  • Messages or calls that reference details of your past orders — that's a strong signal the data was actually used, not just a bluff by a random scammer.
  • Reusing the same password across Dodo's app and other services — a breach of one account is often the entry point attackers use to try credential-stuffing on your other accounts.

How to limit the damage from repeated service breaches

The Dodo Pizza attack is another entry in a long string of 2026 incidents affecting delivery and retail services in Russia. You can't eliminate the risk on the service's side — that responsibility sits with the company and the regulator — but you can reduce the fallout for yourself:

  • Use a separate email for delivery-service sign-ups instead of your main personal address, so a breach at one service doesn't cascade into access to everything else.
  • Never confirm personal details on an inbound call — if something feels off, hang up and call the service back using the number from its official website.
  • Encrypt your traffic when ordering over public Wi-Fi. LiMP VPN hides the contents of your session from others on the same network, though it can't protect against a leak that already happened on the service's own servers.

Sources