A recent cyberattack has targeted Żabka, Poland's largest convenience store chain, compromising its internal systems through a third-party contractor's account. The company confirmed that it detected unauthorized access to its technical systems, which are used to interact with its extensive franchise network. This breach, however, did not affect payment systems, transaction data, the Żappka loyalty app, or the daily operations of its more than 12,800 locations across Poland.
The breach became known after hackers advertised what they claimed to be stolen Żabka data on a cybercrime forum, pricing it at €5,000. Żabka stated that the attack was initiated through an external service provider's account rather than a direct breach of its infrastructure. Following the discovery, the company informed Poland's data protection authority and law enforcement but did not specify the attackers or confirm any ransom demands.
Poland's Minister of Digital Affairs, Krzysztof Gawkowski, reassured the public that customer data, payment information, and retail operations were not impacted. The incident was first reported by the Polish cybersecurity outlet Niebezpiecznik, which indicated that hackers had accessed Żabka's Jira environment. This platform is used for managing software development, technical support, and operational workflows. The hackers also claimed to have obtained employee and contractor information, internal documents, passwords, authentication tokens, API keys, and source code from multiple GitLab repositories.
Niebezpiecznik also noted that the attackers reached out to journalists and companies associated with Żabka to raise awareness of the breach before putting the data up for sale. These claims have not been independently verified, and Żabka has not confirmed the specifics or volume of the data potentially stolen.


