Cyber Incident Victim: Żabka
Timeline
Summary
Żabka confirmed a cyberattack after internal data was offered for sale on a black‑market forum, noting that the intrusion was detected and blocked and that it reached an internal ticketing system used for technical issue reports. The alleged stolen data includes hundreds of thousands of Jira tickets, IT support requests, source code from dozens of projects, employee and contractor details, internal documentation, passwords, access tokens and infrastructure information, while payment systems, the Żappka app and store operations remained unaffected. The company has notified Poland’s data‑protection authority and law‑enforcement agencies and is contacting individuals whose personal data may have been compromised.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 4, 2026, Żabka confirmed that an attacker had gained unauthorized access to some of its internal systems after alleged company data appeared for sale on a cybercrime forum for €5,000. The company stated that the intrusion was detected and immediately blocked. Its investigation indicated that the attacker reached an internal ticketing system used to report and manage technical problems. According to Żabka, payment data, consumer services, the Żappka mobile application and normal store operations were not affected by the breach. The seller claimed to have stolen approximately 541,000 internal issue reports from Jira, nearly 230,000 IT support requests and source code from 89 company software projects. The advertised files also allegedly contained employee and contractor information, internal documentation, passwords, access tokens and details of Żabka’s computer infrastructure. Żabka said it had notified Poland’s data‑protection authority and specialist law‑enforcement agencies. Individuals whose personal information was affected are being contacted directly by the company.

The data was offered for sale two days after Canadian retailer Alimentation Couche‑Tard, the owner of Circle K, announced plans to acquire Żabka for $8.7 billion. Samples of the leaked material suggest that the attacker had obtained access by July 29, 2026, before the acquisition proposal became public. Żabka emphasized that the breach did not compromise payment card details, consumer‑facing services or the functionality of its stores. The company’s response included securing the compromised ticketing system, preserving evidence for investigators and cooperating with authorities to trace the source of the leak. Affected employees and contractors are receiving direct notifications about the potential exposure of their personal data.
The incident occurs amid a rising tide of cyber threats in Poland, where a government report published in April 2026 recorded 682,000 cyber incident reports for 2025, representing a nearly 144 % increase compared with the previous year. Poland’s Digital Affairs Minister Krzysztof Gawkowski has described the country as the most frequently targeted member state in the European Union. Żabka’s confirmation adds to the growing list of organizations confronting sophisticated attacks that seek to exfiltrate internal operational data and source code.
