The Record reported on Monday that ATB, Ukraine's largest grocery chain, confirmed a cyberattack after an extortion message appeared on its website. DataSuckers took credit, asked for $400,000, and threatened to release data it says it took. A countdown timer was later removed, and the site was down when The Record wrote. ATB said it took some services offline for what it called technical maintenance, and denied that customer data was compromised. DataSuckers then posted what it says are samples of stolen data on Telegram and said it would sell the database rather than leak it.
DataSuckers says it holds data on 7.9 million customers, including names, phone numbers, emails, addresses and password hashes. It also claims employee passport details and over 11 million order records. The Record could not independently verify the data or its scale. The report does not say how or when the attackers got in.
The sources say nothing about ATB's forensics, so this is general context, not a view on its denial. A ransom message can come from web server access alone. Copying a database needs a separate route to the records. Database export logs and outbound traffic logs help tell the two apart. If hashes leaked, slow, salted hashing makes guessing passwords costly. Fast, unsalted hashing makes it cheap.