VYPR
breachPublished Aug 4, 2026· 1 source

Polish Convenience Chain Żabka Hacked Via Third-Party Account

Żabka, Poland's largest convenience store chain, confirmed a cyberattack in late July that compromised internal systems through a compromised third-party contractor account, though customer data and operations remain unaffected.

Poland's largest convenience store chain, Żabka, has confirmed a significant cyber intrusion that occurred in late July, leading to the alleged theft of internal corporate data. Attackers reportedly gained access to the company's technical systems by compromising an account belonging to an unspecified external service provider, underscoring the persistent risks associated with supply chain vulnerabilities.

Żabka detected the unauthorized access to systems used for communicating with its franchise network late last week and immediately took steps to block the intrusion. The company has assured the public that critical systems such as payment processing, transaction data, the popular Żappka loyalty application, and day-to-day store operations were not affected by the breach. This assurance was echoed by Poland's Minister of Digital Affairs, Krzysztof Gawkowski, who stated that authorities were promptly informed and that customer data and payment information were secure.

The incident came to light after anonymous hackers began advertising what they claimed to be stolen Żabka data for sale on a cybercrime forum, with an asking price of €5,000 (approximately $5,800). The hackers also claimed to possess sensitive information including employee and contractor details, internal documentation, passwords, authentication tokens, API keys, and source code from multiple GitLab repositories.

According to reports from Polish cybersecurity outlet Niebezpiecznik, which analyzed samples of the allegedly stolen data, the attackers appear to have gained access to Żabka's Jira environment. Jira is a widely used platform for managing software development projects, technical support, and operational workflows, suggesting a deep level of access within the company's technical infrastructure.

Żabka has stated that it has notified Poland's data protection authority and relevant law enforcement agencies following the discovery of the attack. The company has not attributed the incident to any specific threat actor group nor has it confirmed whether a ransom demand was made. The full extent and nature of the data exfiltrated are still under investigation.

Niebezpiecznik also reported that the attackers proactively contacted journalists and companies collaborating with Żabka to publicize the breach before listing the data for sale. These claims have not been independently verified by Żabka, which has not provided further details on the volume or specifics of the compromised data beyond the initial confirmation of unauthorized access.

This incident highlights the critical importance of robust third-party risk management. Compromised credentials of external vendors continue to be a primary vector for sophisticated cyberattacks, enabling threat actors to bypass direct defenses and infiltrate corporate networks. The reliance on interconnected systems and third-party access creates a complex attack surface that organizations must diligently monitor and secure.

Synthesized by Vypr AI