← Blog

Dodo Pizza Breach: Customer Data Hit in Sep 2026

Share on X

Dodo Pizza confirmed on September 29, 2026 that attackers breached its systems over the weekend of September 27–28. In a Telegram notice from the Russian chain’s official channel, the company said hackers may have accessed customer personal data and order details for some patrons — while stressing that payment card data is not stored on its systems and was not compromised. The Record and Meduza covered the same confirmation the same day.

Separately — and this part is an unverified claim, not a company figure — a group calling itself DataSuckers advertised what it said was roughly 68 million Dodo Pizza customer records plus about 15 years of order history, with an asking price around $100,000. Dodo Pizza has not confirmed that census. Treat the 68 million number as actor marketing until forensics or a later company update says otherwise.

Canonical record: https://breachhistory.com/dodo-pizza/dodo-pizza-datasuckers2026.

What happened

The company timeline is short and unusually clear for a food-delivery brand of this size.

Attackers reached Dodo Pizza systems on September 27–28, 2026. By September 29 the chain published a customer-facing notice on Telegram, told Russia’s communications regulator Roskomnadzor, said it had blocked the unauthorized access, and said an investigation was underway. That sequence — weekend intrusion, Monday disclosure, regulator notice, access cut — is the verified spine of the Dodo Pizza data breach story.

Dodo Pizza is not a neighborhood pizza shop that got unlucky. The brand runs roughly 1,500 locations across about 28 countries. Customer accounts, delivery addresses, and order histories sit in digital systems that support that footprint. When those systems are breached, the blast radius is not limited to one city or one franchise.

What the company has not yet published is a CVE-style root-cause write-up, a precise affected-customer headcount, or a field-by-field dump inventory. The September 29 notice is a confirmation of intrusion and possible customer-data access, not a finished forensic report. Expect follow-on updates if the investigation revises what left and for how many people.

What was exposed

Dodo Pizza’s own words matter here more than the actor’s sales pitch. The company said hackers may have obtained, for some customers:

  • Names
  • Delivery or contact addresses
  • Phone numbers
  • Email addresses
  • Dates of birth
  • Order details

That set is classic delivery-platform PII. Name plus phone plus address is enough to script highly convincing “your Dodo order failed — confirm payment” SMS and voice scams. Email plus date of birth adds account-recovery and loyalty-fraud angles. Order details — what you ordered, when, and where it went — let a scammer sound like they already work inside the app. “We see your last order to [street] didn’t complete; validate the card ending in …” is the kind of line that works after a pizza-chain breach even when the pizza chain never held the card number.

The company framed exposure as possible and for some customers, not as a finished census of every account in every country. If you ordered through Dodo Pizza around the intrusion window — or hold an account tied to the brand’s apps and sites — assume your contact and order profile may be in play until the company or a regulator publishes a narrower list.

Order history is easy to underestimate. A year of pizza deliveries maps household routines: late-night patterns, office addresses, kids’ parties, hotel stays. Combined with a phone number, that history fuels social engineering that never needs a password vault.

What was not exposed

Dodo Pizza’s clearest negative finding: payment data is not stored on its systems and was not compromised. For a chain that takes cards and digital wallets at scale, that is the single most important containment claim in the notice.

To be clear: “cards not stored / not compromised” is not the same as “no financial risk.” Attackers with name, phone, email, address, date of birth, and recent order context can still run card-not-present social engineering, fake refund calls, and phishing pages that harvest a fresh card the company never held. The vault claim reduces one channel; it does not cancel phishing.

What this is not, based on the company record: a confirmed 68-million-customer disclosure, a confirmed public dump of every field DataSuckers advertised, or a payment-card breach. Do not collapse the actor’s sale listing into the company’s Telegram facts.

As of the September 29 notice, Dodo Pizza also said access had been blocked and the investigation was ongoing. Absence of a detailed public dump from the company is not a promise the stolen subset will never surface later on forums or in broker chats.

The DataSuckers claim — unverified

Unverified claim: DataSuckers publicly claimed roughly 68 million Dodo Pizza customers, about 15 years of order history, and a sale price near $100,000. Trade press including The Record reported that actor narrative alongside the company’s confirmation. Dodo Pizza has not endorsed the 68 million figure or the 15-year corpus description.

Why the gap matters. Extortion and data-sale crews routinely inflate headcounts. A brand with 1,500 locations across 28 countries can have a large customer database without matching a tidy “68 million unique people” marketing line. Fifteen years of orders, if real, would be unusually deep historical retention — possible for a digitally native chain, not proven by a leak-site caption alone.

How to read both tracks at once: the breach is verified; the possible data types are company-stated; the payment negative finding is company-stated; the 68 million / $100k package is an actor claim. Until Dodo Pizza, Roskomnadzor, or independent forensic reporting attaches a confirmed count, cite the actor number only as unverified.

How the attack worked

Dodo Pizza has not published a technical post-mortem yet. The attested facts stop at unauthorized access over September 27–28, possible customer-data reach, access blocked by the September 29 notice, regulator notification, and continuing investigation. Speculating past that — naming a VPN zero-day, an SSO misconfiguration, or a specific malware family — would invent facts the company has not released.

The shape that does exist is familiar for large quick-service and delivery brands: internet-facing order and loyalty systems hold dense customer profiles; an attacker gets inside; containment follows detection; customer notification leads with possible PII and a payment-data carve-out. Root cause may arrive later if Dodo Pizza publishes a fuller update or if regulators compel more detail.

For other restaurant and delivery operators, the immediate lesson is not a novel exploit string. It is how much identity and routine data a pizza order really carries — and how fast that package becomes phishing fuel once copied.

Who is at risk

Start with anyone who held a Dodo Pizza customer account or placed orders through the brand’s digital channels in the footprint the company serves — roughly 1,500 locations in about 28 countries. The company has not published a country-by-country affected list. Do not assume you are safe because you ordered outside Russia; the brand’s systems support a multinational map.

Individual customers and loyalty users

If your name, phone, email, address, or date of birth sat in Dodo Pizza’s customer systems, treat them as potentially exposed. Expect SMS and Telegram messages that cite a “failed delivery,” a “loyalty points freeze,” or a “mandatory re-verification after the September breach.” Real Dodo support will not ask you to paste a card number or one-time password into a cold chat.

Households that share delivery addresses

Shared apartments, dorms, and family phones widen the blast radius. A roommate’s order history plus your phone number is enough for a scammer to sound like they know the household. Warn people who share your delivery address even if they never created their own Dodo account.

Corporate and office ordering

Offices that used Dodo Pizza for team lunches may have company addresses and employee contact numbers in order logs. Attackers can impersonate facilities or admin staff asking to “re-approve the catering card after the Dodo Pizza breach.” Finance assistants who book food for others are high-value pivots.

Customers in all 28 countries

Multinational QSR breaches create uneven notice culture. Some markets hear about the incident through Telegram and Russian-language press first; others through English trade coverage days later. If you use the Dodo Pizza app or site anywhere in the brand’s footprint, watch official channels rather than waiting for a perfectly timed email in your language.

Industry and campaign context

Food delivery and quick-service chains concentrate exactly the fields criminals want for local social engineering: phones, addresses, emails, and recent purchase context. Unlike a pure payment processor, the restaurant brand often holds the lifestyle detail that makes a phishing call feel “inside.” A confirmed Dodo Pizza breach 2026 incident sits in that pattern even before any actor census is proven.

Russia’s Roskomnadzor sits in the notification path for domestic personal-data incidents of this kind. Dodo Pizza said it notified the regulator. That is process, not a finished public fine or a published technical audit. Watch for later regulator statements if the investigation expands the field list or documents unlawful processing beyond the weekend intrusion itself.

Actor branding matters for readers scanning leak trackers. DataSuckers’ listing is the unverified noise layer around a company-confirmed event. Catalog readers should keep those layers separate the same way they would for any ransomware or data-sale claim that outruns victim confirmation.

Compared with pure leak-site theater elsewhere in September 2026, Dodo Pizza’s notice is relatively concrete on payment data and relatively cautious on census. That combination — confirmed breach, possible PII, cards out, actor count unverified — is the accurate public picture as of September 29.

What the company and regulators said

Dodo Pizza’s September 29 Telegram posture mixes apology-adjacent transparency with containment claims. The company acknowledged the September 27–28 attack, said customer personal data and order information may have been accessed for some patrons, said payment data is not stored and was not compromised, said unauthorized access was blocked, said Roskomnadzor was notified, and said the investigation continues.

English-language readers can follow the same facts through The Record’s report on the Russian pizza chain confirmation and Meduza’s same-day news brief. Both outlets distinguish — or sit alongside — the company’s notice and the DataSuckers sales narrative. Prefer those primary and trade sources over random paste sites claiming “68 million confirmed.”

As of the first company notice, there was no published administrative fine and no finished public forensic annex. Services and ordering posture will evolve with the investigation; identity-theft risk from data already copied does not wait for a fine.

What you should do

If you ordered from Dodo Pizza or hold an account in any of the roughly 28 countries where the brand operates, work this list in order.

  1. Treat the breach as real even if you never see a personal email. The company confirmed intrusion; personal notices may lag or arrive through app and Telegram channels unevenly across markets.
  2. Change your Dodo Pizza password and anywhere you reused it. Prefer a password manager and a unique string. Rotate related food-delivery and loyalty logins if they shared the same credential.
  3. Turn on MFA wherever the Dodo Pizza app or site allows it. Harden email MFA too — account recovery usually runs through the inbox that may already be in the leak set.
  4. Watch phones and messaging apps for delivery-themed phishing. Cold SMS, WhatsApp, or Telegram notes that already know your address or last order are hostile until proven otherwise.
  5. Do not “re-enter a card to keep your account.” The company says payment data was not stored and not compromised. Any message demanding a fresh card “because of the breach” is a harvest attempt.
  6. Verify refund and support calls out of band. Hang up and use contact paths from the official Dodo Pizza site or app, not from the message body.
  7. Office orderers: warn facilities and finance. Department-aware phishing about “catering re-enrollment after the Dodo Pizza data breach” will target people who approve food spend.
  8. Monitor for SIM and account-recovery fraud. Name + phone + date of birth is enough for carrier and inbox takeover scripts that never need your pizza password.
  9. Keep the company notice if you receive one. Banks and employers sometimes ask for proof of third-party exposure scope.
  10. Follow the canonical BreachHistory page for count updates. Start at /dodo-pizza/dodo-pizza-datasuckers2026 if Dodo Pizza revises the field list or publishes a confirmed census after forensics deepen.

Phishing patterns to expect

After a names-phones-emails-addresses-plus-orders breach, social engineering gets local fast. A convincing SMS might open with your real street, claim the September 27–28 incident forced a “mandatory wallet re-link,” and push a shortened URL to a clone of the Dodo Pizza checkout that asks for a full card. Another pattern: a voice call from someone who already knows your last order and date of birth, pretends to be security, and asks you to read an SMS one-time code “to cancel fraudulent pizzas.” Real support will not need a live OTP on a cold call.

Telegram-native bait is especially plausible here because the company used Telegram for the official notice. Attackers will spoof channel names, recycle screenshots of the real dodorus/511 post, and attach “claim compensation” bots. Open the official channel from a bookmark you already trust — do not follow compensation links from strangers forwarding “Dodo breach payout” messages.

Corporate catering fraud will cite the incident as the reason to change a supplier IBAN or card-on-file. Teach anyone who pays for office food to verify bank-detail changes by phone using a number already on file.

Loyalty-point panic (“your 15 years of orders will be deleted unless you verify today”) will try to launder the unverified DataSuckers marketing line into urgency. You do not need to authenticate with a stranger to “preserve order history.”

What “was I affected” looks like in practice

You may be affected if you held a Dodo Pizza customer profile or placed delivery or pickup orders through the brand’s digital systems before the September 27–28 intrusion window, especially if you later receive an official notice. The company has said personal data and order details may have been accessed for some customers; it has not published a global headcount. Prefer Dodo Pizza’s Telegram channel and reputable trade press over actor sales pages.

Payment cards: company position is not stored, not compromised. Actor census: ~68 million customers and 15 years of orders at ~$100k asking price — unverified. Working public facts as of September 29, 2026 remain the weekend attack, Monday disclosure, Roskomnadzor notice, blocked access, ongoing investigation, and the possible PII and order-detail list above.

Canonical record and sources

BreachHistory indexes this incident at https://breachhistory.com/dodo-pizza/dodo-pizza-datasuckers2026: company-confirmed by Dodo Pizza, attack September 27–28, 2026, notice September 29 via Telegram, possible exposure of names, addresses, phones, emails, dates of birth, and order details for some customers, payment data not stored and not compromised, Roskomnadzor notified, access blocked, investigation ongoing, brand footprint about 1,500 locations in roughly 28 countries. The DataSuckers ~68 million / ~$100k package is recorded as an unverified actor claim, not a company-confirmed count.

Authoritative outbound sources for this write-up are Dodo Pizza’s September 29 Telegram notice, The Record’s report on the confirmation, and Meduza’s September 29 brief.

If Dodo Pizza or Roskomnadzor later revises the field list or publishes a confirmed census, the catalog should move with those statements. Until then: a verified weekend breach at a multinational pizza chain; cards stayed out of the company vault story; contact and order data may not have; rotate credentials, harden MFA, refuse cold card re-entry, and verify every urgency message out of band — without treating the actor’s 68 million figure as fact.