Polish retail giant Żabka breached via external service provider: data up for sale
Hackers are only asking a “symbolic” €5,000 for the data.

Image by Cybernews.
- Żabka confirmed unauthorized access through an external provider, but said transactions and business operations remained secure.
- A seller seeks €5,000 for data allegedly covering 541,000 Jira issues, source code, employee records and production credentials.
- Żabka blocked access, notified Poland’s data regulator and is informing people whose personal data may be affected.
- Researchers warn the exposed infrastructure details and credentials could help attackers exploit vulnerabilities and penetrate more systems.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Żabka Polska, Poland’s largest convenience-store chain, suffered a major cybersecurity incident. At the same time, an anonymous threat actor is advertising the allegedly stolen data, offering it for 5,000 euros for the full package, claiming it contains 541,000 Jira Issues and 2.7 million user references, among other things.
“We confirm that at the end of last week, we received information regarding a suspected unauthorized access to selected technical resources within our network through an external service provider. The unauthorized access was detected and promptly blocked in accordance with our established security procedures,” the Żabka spokesperson told Cybernews.
Based on the initial company’s findings, the security of transactional data and the continuity of our business operations have not been compromised.
Żabka confirmed that it immediately escalated the matter to the Data Protection Officer of Żabka Polska sp. z o.o. and reported it to the President of the Personal Data Protection Office (UODO) in line with applicable legal requirements and internal procedures.
“Individuals whose personal data may have been affected by the incident are being informed on an ongoing basis. The security of our data and systems remains our highest priority. From the outset, we have focused on swift response measures, full cooperation with the relevant authorities, and transparent communication with individuals who may have been impacted by this situation,” the statement reads.
The company also continues to monitor the situation and takes “all necessary steps to further strengthen the security of our systems and infrastructure.”
Data for sale
The threat actor under the throwaway moniker Lumia is looking for data buyers on an illicit marketplace, one of the many notorious Breach Forum mirrors.
“The full dataset is now being offered for sale at a symbolic price of €5,000,” the post by the new account reads.
If the claims of data theft from “a significant data breach” are true, attackers during last weeks compromise managed to steal internal employee records, confidential project documentations, source code, and credentials for production systems.
The seller claims to have obtained a massive amount of data and has provided a data sample. The post names some of the internal systems affected.
“Full names, corporate email addresses (@zabka.pl), JIRA usernames, account IDs, and employee/contractor directory information extracted from approximately 541,000 JIRA issues. Includes 2.7 million user references across 20+ vendor domains, including Accenture, Netguru, Onwelo, BlueSoft, and Sygeon,” the hacker claims.
The sensitive internal documentation allegedly covers JIRA exports of IT service desk operations (229,734 tickets), as well as the Nowa Kasa POS system, the ZSS sales system, Cyberstore, the zMarket order and inventory management platforms, and the SAP ERP core enterprise resource planning system and its MDG data governance module.
The hackers also allegedly copied 89 internal source code (Git) repositories containing nearly 12,000 files for Żabka’s retail platform, backend microservices, frontend apps, and other infrastructure.
The posting also claims to include dozens of sensitive credentials for production systems, such as GitLab Personal Access tokens reused across all compromised repos, database admin passwords, .env files with hardcoded tokens, “direct SSH access patterns to individual store servers,” among others.
Sensitive business intelligence includes 4,000 unvalidated mentions of bank accounts, retail operations data, and vendor relationships.
According to Rasa Jurgutyte, a Cybernews security researcher who reviewed the data samples archived in a 3.1-megabyte ZIP file, the exposed Jira tickets resemble legitimate ones based on their format, data, and Polish comments.
The exposed data sample comprises 48 JSON files, each representing an internal Jira project, with some issue samples. An additional 89 files in another folder contain GitLab references: samples from main branches as well as the OAuth2 key exposed as a URL parameter.
“Exposed blueprints of infrastructure, credentials, and potentially source code are significant enough to enable attackers to exploit known vulnerabilities and move laterally,” Jurgutyte warns.
Żabka operates a network of 13,063 stores across Poland and Romania, carrying out 4.3 million transactions every day, according to the company’s “About Us” page. The company’s sales to end customers were 31.1 billion Polish zloty ($8.34 billion) in 2025.