Żabka, Poland's largest convenience store chain, confirmed a cyberattack that resulted in unauthorized access to its internal technical systems. The intrusion was detected late last week and immediately blocked. The company stated that the attack did not impact payment systems, transaction data, the Żappka loyalty app, or daily store operations.
Attackers gained access by compromising an account belonging to an external service provider, rather than directly breaching Żabka's own infrastructure. This indicates a supply chain attack vector, where a vulnerability in a vendor's security leads to a breach of the primary target.
Previously unknown hackers advertised what they claimed was stolen Żabka data for sale on a cybercrime forum. Samples provided by the attackers suggested access to Żabka's Jira environment, which is used for project management and technical support. The hackers also claimed to possess employee and contractor information, internal documentation, passwords, authentication tokens, API keys, and source code from GitLab repositories.
Żabka notified Poland's data protection authority and law enforcement agencies about the incident. Poland's Minister of Digital Affairs, Krzysztof Gawkowski, confirmed that customer data, payment information, and retail operations were not affected, based on information provided by the company. The company did not disclose whether a ransom demand was made.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Polish convenience store chain Żabka experienced a cyberattack that exposed internal company systems after attackers compromised a third-party contractor's account. The breach did not affect payment systems, transaction data, the Żappka loyalty app, or day-to-day store operations, according to the company and Polish authorities. This incident highlights the supply chain risk posed by third-party vendor access to internal systems.