Summary
- The access involved technical resources used to exchange information between Żabka and its franchisees.
- An account belonging to an external service provider was used and blocked after the activity was detected.
- Żabka reported the incident to Poland’s regulator, law enforcement, and CERT Polska within its response process.
Attackers used an external service provider’s account to access technical resources supporting communication between Żabka and its franchise network.
The Polish convenience retailer said it detected the unauthorised access towards the end of last week and blocked it under its incident-response procedures. The affected resources support information exchange between Żabka, as franchisor, and the independent operators running its shops.
Żabka reported the personal-data breach to the president of Poland’s Personal Data Protection Office within 48 hours of discovery. It subsequently notified specialist law-enforcement bodies and the Central Bureau for Combating Cybercrime and entered contact with CERT Polska.
The company said transactional information and consumer services were unaffected. It also reported no impact on the confidentiality of information held in the Żappka application or on the operational activity of its shops.
That separation indicates that the compromised resources did not provide direct control over the retailer’s payment environment or customer-facing application, although Żabka has not published sufficient architectural detail to establish how the affected and unaffected systems were segmented.
The disclosure does not identify the service provider, explain how its account was compromised, or state what permissions it carried. It also does not describe the information available through the resources used for franchise communications or the number of people whose data may be involved.
Claims that attackers obtained source code, access tokens, credentials, or other development assets have circulated outside the company’s statement. Żabka has not confirmed those claims, and they should not be treated as established evidence of the breach’s scope.
The use of an authorised supplier account presents a different detection problem from exploitation of an unknown external vulnerability. Activity can pass initial identity checks because the account is expected to access the environment. Monitoring must then distinguish legitimate support or integration work from unusual behaviour within an otherwise valid session.
Supplier accounts can also outlive the projects for which they were created or accumulate permissions as a commercial relationship expands. Where the provider manages its own authentication devices and workforce, the customer may have limited visibility into how the credential is stored, shared, or protected before it reaches the customer’s environment.
Żabka’s franchise model increases the operational importance of shared technical resources. Information must move between the central business and thousands of shop operators covering ordering, product availability, commercial administration, support, and other routine processes. An attacker reaching those exchanges could create exposure even without affecting checkout or payment systems.
The regulatory notification confirms that Żabka assessed the event as a breach involving personal information, but it has not identified the data categories, number of affected individuals, or likely consequences. Those findings may change as investigators reconstruct the account’s activity and determine whether information was viewed or removed.
The confirmed facts remain limited to unauthorised access through an external provider’s account, containment, and notification. The more extensive theft claims remain unverified.



