Żabka Cyberattack Exposes Internal Systems via Third-Party Compromise
Poland's largest convenience store chain, **Żabka**, has confirmed a cyberattack that exposed internal company systems. Attackers allegedly gained access by compromising an account belonging to an external service provider, leading to the theft of corporate data.
A recent cyberattack on **Żabka**, Poland's prominent convenience store chain, has led to the exposure of internal company systems. The incident, which became public after hackers offered what they claimed was stolen data for sale on a cybercrime forum, highlights the critical vulnerabilities introduced by third-party vendor relationships.
**Żabka** detected unauthorized access to technical systems, primarily those used for communication within its franchise network, late last week. The company promptly blocked the intrusion and initiated an investigation.
### Third-Party Compromise Identified
According to **Żabka**, the attackers did not directly breach the company's core infrastructure. Instead, they gained access by compromising an account belonging to an unspecified external service provider. This method underscores a common attack vector where adversaries exploit weaker links in the supply chain to infiltrate target organizations.
### Impact on Operations and Data
While internal systems were affected, **Żabka** has assured the public that critical consumer-facing operations remain secure. The company stated that payment systems, transaction data, the **Żappka** loyalty application, and day-to-day store operations were unaffected by the breach.
**Krzysztof Gawkowski**, Poland's Minister of Digital Affairs, corroborated this, confirming that based on information provided to the government, customer data, payment information, and retail operations were not compromised.
### Nature of Stolen Data
The incident gained wider attention after Polish cybersecurity outlet **Niebezpiecznik** reported that hackers had posted samples of the allegedly stolen data online. Analysis of these samples suggests that the attackers may have accessed **Żabka**'s **Jira** environment, a platform widely used for project management, technical support, and workflow operations.
The hackers also claimed to possess a trove of sensitive information, including employee and contractor details, internal documentation, passwords, authentication tokens, **API** keys, and source code from multiple **GitLab** repositories. **Żabka** has not yet confirmed the specific nature or volume of any stolen data.
### Regulatory Response
Upon discovering the attack, **Żabka** promptly notified Poland's data protection authority and law enforcement agencies, demonstrating adherence to regulatory requirements. The company has not attributed the attack to a specific threat actor nor disclosed whether any ransom demands were made.
