CSIDB logo
Incident

Żabka

Incident posture

Attack window
Jul 2026
Location
Poland
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 19:01

Linked entities

Victim
Żabka
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jul 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

Żabka confirmed a cyberattack after internal data appeared for sale on a black‑market forum, noting that an attacker had accessed its internal ticketing system but was blocked before payment systems, consumer services, its mobile app or store operations were affected. The alleged dump includes roughly 541,000 Jira issue reports, nearly 230,000 IT support tickets and source code from 89 repositories, together with employee and contractor details, internal documentation, passwords, access tokens and infrastructure information; the company has notified Poland’s data‑protection authority and law‑enforcement agencies and is contacting affected individuals. A single GitLab access token found in the repository dumps could, if still active, allow cloning of the firm’s entire development platform, and the leak surfaced shortly after a major acquisition offer was made, though timestamps indicate the data was gathered before the offer became public. Investigators note that the typical method for such breaches involves stolen employee credentials harvested by infostealer malware, which matches the observed pattern.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On August 2, 2026, a newly created forum account posted a single message offering what it described as a complete data dump from Żabka Polska for €5,000. Żabka confirmed the following day that an attacker had gained unauthorized access to some of its internal systems after the alleged data appeared on a black‑market forum. The company stated that the intrusion was detected and immediately blocked, and its investigation indicated that the attacker had reached an internal ticketing system used to report and manage technical problems. Żabka said that payment data, consumer services, its Żappka mobile application and normal store operations were not affected by the breach. The firm notified Poland’s data‑protection authority and specialist law‑enforcement agencies and began contacting individuals whose personal information was implicated.

The seller claimed to have exfiltrated around 541,000 Jira issue reports, nearly 230,000 IT service‑desk tickets, and source code from 89 company software projects hosted on GitLab. The advertised material also supposedly contained employee and contractor information, internal documentation, passwords, access tokens and details of Żabka’s computer infrastructure. Independent verification of sample files showed that 48 Jira exports totaled 541,463 issues, matching the advertised figure, and the IT service‑desk export corresponded exactly to the stated total. However, the sample did not contain the claimed 35,206 GDPR references or the roughly 4,000 bank‑account mentions. The repository dumps each included a 62‑character GitLab access token embedded in the clone URL; the listing asserted that, if valid and still active, this token could enable cloning of Żabka’s cs‑market platform comprising 44 devops repositories, 26 backend services, seven frontends, an API gateway and associated tooling. The samples additionally revealed live‑looking secrets such as Cloudflare API keys, a MongoDB administrator password and messaging broker credentials residing within infrastructure code.

Żabka operates a franchise network of more than 11,000 convenience stores across Poland, having been founded in 1998 and serving millions of customers daily. The incident occurred amid a surge in cyber threats in Poland, where a government report published in April 2026 recorded 682,000 cyber incident reports for 2025, an increase of nearly 144% over the previous year, and the Digital Affairs Minister described Poland as the most frequently targeted country in the European Union. The data dump appeared two days after Alimentation Couche‑Tard announced a €7.56 billion offer to acquire Żabka Group on July 31, 2026, although timestamps in the sampled files suggest the data was collected before the acquisition became public. Żabka’s response included detecting and blocking the intrusion, conducting an investigation, notifying regulators and law enforcement, and directly contacting affected individuals. The company reiterated that no payment data, consumer services, Żappka functionality or store operations were compromised.

Sources

Sources available to members: 2 sources.

CSIDB