Żabka, Poland’s largest convenience store chain, disclosed a cyberattack after attackers used a compromised account belonging to an external service provider to gain unauthorized access to internal technical systems. The company said it detected and blocked the intrusion late last week, notified Poland’s data protection authority and law enforcement, and reported that payment systems, transaction data, the Żappka loyalty app, and store operations were not affected. Poland’s Minister of Digital Affairs said authorities were informed promptly and that available information indicated customer data and retail operations were not impacted.
The incident surfaced after hackers allegedly offered stolen Żabka data for sale on a cybercrime forum for €5,000 and published sample files online. Reporting on the sample indicated the exposed material may include about 541,000 Jira issues, roughly 229,734 service-desk tickets, and source code from 89 GitLab repositories, along with employee and contractor data, internal documentation, passwords, authentication tokens, and API keys. Review of the sample also pointed to a GitLab access token embedded across repository dumps and other live-looking secrets, including Cloudflare API keys, a MongoDB admin password, and messaging broker credentials, although Żabka has not confirmed the full scope of the allegedly stolen data.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
A newly created forum account advertised an alleged Żabka Polska dataset for €5,000, claiming it included about 541,000 Jira issues, 229,734 service-desk tickets, and source code from 89 GitLab repositories. The seller account reportedly had no trading history and posted the listing 14 minutes after creation.
Alimentation Couche-Tard announced a €7.56 billion offer for Żabka Group. One report noted the later leak listing appeared two days after this announcement.
Żabka publicly disclosed a cyberattack affecting internal company systems and said the intrusion came through a compromised third-party account rather than a direct breach of its own infrastructure. The company said it notified Poland’s data protection authority and law enforcement, and Poland’s Minister of Digital Affairs said authorities were informed promptly.
Reporting said the attackers posted sample data online and contacted journalists and companies working with Żabka to publicize the breach before advertising the data for sale. Niebezpiecznik reported the attackers appeared to have accessed Żabka’s Jira environment.
Ransomnews reviewed the sample archive attached to the forum listing and found the headline counts for Jira issues and service-desk tickets largely matched the evidence provided, while some secondary claims did not. The sample reportedly included a GitLab access token reused across 89 repository dumps and live-looking secrets such as Cloudflare API keys, a MongoDB admin password, and messaging broker credentials.
Żabka said attackers gained unauthorized access to internal technical systems through a compromised account belonging to an external service provider or contractor. The company said it detected the intrusion late last week and immediately blocked it, while stating payment systems, transaction data, the Żappka app, and store operations were unaffected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcetherecord.media
Open sourcezabka.pl
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.