Żabka store sign
Image: Żabka Group

Polish convenience store chain Żabka hacked through third-party account

A cyberattack on Poland's largest convenience store chain, Żabka, has exposed internal company systems after attackers allegedly stole corporate data through a third-party contractor's account.

The company confirmed on Tuesday that it detected unauthorized access to technical systems used to communicate with its franchise network late last week and immediately blocked the intrusion. According to Żabka's statement, payment systems, transaction data, the Żappka loyalty app, and day-to-day store operations were unaffected.

"We assure you that the security of transaction data and consumer services, the confidentiality of Żappka app data, and our operational activities remain unaffected," the company said. It has more than 12,800 locations in Poland.

The disclosure came after previously unknown hackers advertised what they claimed was stolen Żabka data for sale on a cybercrime forum for €5,000 ($5,800).

According to the company, the attackers gained access by compromising an account belonging to an unspecified external service provider rather than breaching Żabka's own infrastructure directly.

The retailer said that after discovering the attack, it notified Poland's data protection authority and law enforcement agencies. The company did not attribute the attack to a specific threat actor or disclose whether a ransom demand was made. Żabka did not immediately respond to a request for comment.

Poland's Minister of Digital Affairs, Krzysztof Gawkowski, said on Tuesday that authorities had been informed promptly and confirmed that, based on information provided to the government, the breach did not affect customer data, payment information or retail operations.

The incident became public after Polish cybersecurity outlet Niebezpiecznik reported that hackers had posted samples of the allegedly stolen data online.

Based on those samples, the publication said the attackers appeared to have gained access to Żabka's Jira environment, an internal platform commonly used by companies to manage software development projects, technical support tickets and operational workflows.

The hackers also claimed to possess employee and contractor information, internal documentation, passwords, authentication tokens, API keys, and source code from multiple GitLab repositories.

Niebezpiecznik also reported that the attackers contacted journalists and companies working with Żabka to publicize the breach before advertising the data for sale. Those claims have not been independently verified, and Żabka has not confirmed the nature or volume of any stolen data.

Get more insights with the
Recorded Future
Intelligence Cloud.
Learn more.
Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.