Dodo Pizza says a cyberattack may have exposed some customers’ delivery addresses, contact details and order contents. In a September 28 statement, the company said its IT system had been attacked that day and the day before. It said it had blocked the attackers’ access, while an internal investigation continued.
The disclosure gives customers two different things to watch for: possible misuse of personal information, and a forced sign-out that Dodo says is a protective measure. Being logged out does not, on its own, identify whose records may have been exposed.
A pizza order contains more than a purchase
Dodo listed names, addresses, email addresses, telephone numbers, dates of birth and the contents of orders as information that could have become accessible. Its wording refers to some customers; the statement does not provide a customer count or a country-by-country breakdown.
That combination matters because it connects a person to a place and a familiar transaction. If obtained by a scammer, an order detail could make a message about a delivery problem or refund seem credible. Knowing an address or what someone ordered would not make the sender genuine. This is a possible consequence of the data exposure, rather than evidence that such follow-on messages have already been sent in this incident.
The company’s reassurance about payments is narrower than a general all-clear: Dodo says it does not store payment data and that those details are safe. The statement still identifies several other categories of personal information at risk. As the recent Belnet email breach also illustrates, sensitive information can be exposed without the disclosure being about stolen card numbers.
Why customers may be signed out
Dodo says users may be logged out as one of its account-protection measures. It also says it notified Russia’s communications regulator, Roskomnadzor, and blocked the intruders’ access. Those are the company’s reported response steps; the investigation was still ongoing when it published the notice.
If the app asks you to sign in again, open the app you already use directly. An unsolicited text offering to “restore” access, issue compensation or verify an order should not become the route back into the account. Check any request inside the service, and do not give a caller or message sender your sign-in code or card details. A familiar order description is context, not authentication.
The scale and entry point remain undisclosed
The notice appeared on Dodo Pizza’s Russian Telegram channel at 18:57 UTC on September 28. It confirms an attack and warns of possible exposure; it does not establish how many records were copied, name an attacker or explain how access was obtained. It also does not establish that customers in every market were affected.
For now, the useful distinction is between what the company has confirmed and what it is still investigating: the attack occurred, access has reportedly been blocked, and certain customer information may have been exposed. Protective logouts and the absence of stored payment data do not settle the remaining questions about that information.
References
- Dodo Pizza Russia. “Statement on the cyberattack and possible customer-data exposure.” September 28, 2026. Official company statement.

