Breaches · 9h ago

ATB Extortion Leak Shifts Focus to Alleged Theft

ATB says some online services were taken offline after DataSuckers posted a $400,000 extortion demand on the retailer’s site and then released sample data on Telegram when ATB denied a customer-data compromise. The website was unavailable when the report was filed, and ATB said the site message did not affect data security.

The group says it has names, phone numbers, email and physical addresses, password hashes, and employee passport data, plus records of more than 11 million orders. Public samples change the incident from a website outage into a claim of stolen identity and order data, because once fragments are posted the pressure moves into fraud, doxxing, and proof-of-theft disputes even if the full database never appears.

For consumer-facing retailers, the exposure does not end when the site comes back up: if the samples are real, customer support, fraud monitoring, and employee safety work all inherit the blast radius. What remains unresolved is the authenticity and scale of the alleged theft, but the public leak has already raised the cost of treating this as an outage-only event.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-05

Editions

Related stories