Żabka says hackers used a third-party contractor account to access internal franchise and development systems

Poland’s largest convenience store chain, Żabka, says hackers got into internal company systems by compromising an external service provider’s account. The company said payment systems, transaction data, the Żappka loyalty app, and store operations were not affected, but reporting indicates the attackers may have reached Jira and GitLab environments and stolen employee and contractor data, passwords, authentication tokens, API keys, internal documents, and source code.
Why it matters: This matters because a compromise of internal systems and developer platforms can create follow-on risk even if customer payments were not touched. Żabka, its franchisees, contractors, and partners should review exposed credentials and tokens, rotate secrets, and watch for phishing or extortion tied to the stolen data.

Sources

Polish convenience store chain Żabka hacked through third-party account
2026.08.04 100% relevant
This article appears to be the first tracked report establishing Żabka’s breach, the third-party account entry point, and the likely exposure of internal Jira/GitLab data and secrets.
← Back to all stories