Poland’s largest convenience store chain, Żabka, says hackers got into internal company systems by compromising an external service provider’s account. The company said payment systems, transaction data, the Żappka loyalty app, and store operations were not affected, but reporting indicates the attackers may have reached Jira and GitLab environments and stolen employee and contractor data, passwords, authentication tokens, API keys, internal documents, and source code.
Why it matters: This matters because a compromise of internal systems and developer platforms can create follow-on risk even if customer payments were not touched. Żabka, its franchisees, contractors, and partners should review exposed credentials and tokens, rotate secrets, and watch for phishing or extortion tied to the stolen data.
2026.08.04
100% relevant
This article appears to be the first tracked report establishing Żabka’s breach, the third-party account entry point, and the likely exposure of internal Jira/GitLab data and secrets.
← Back to all stories