
Polish prosecutors investigate Żabka data breach after hackers leak internal records
Prosecutors in Poznan have opened an inquiry into an early August cyberattack on retail chain Żabka, in which hackers compromised technical systems via a third-party account and offered 541,000 internal records for 5,000 euros.
Legal proceedings initiated in Poznań
The Poznań-Wilda District Prosecutor's Office in western Poland has opened a formal investigation into a cyberattack against convenience store operator Żabka. The inquiry focuses on potential offenses under Article 267, Paragraph 1 of the Polish Penal Code, which governs the unlawful acquisition of information by bypassing or breaking electronic and computer security measures. Under Polish law, prosecution under this statute proceeds upon a formal motion by the injured party, with statutory penalties ranging from fines and restriction of liberty to up to two years of imprisonment. Investigators are examining digital traces to determine the exact method used to penetrate the retailer's infrastructure. Regional authorities confirmed that the investigation remains at an early stage and that no formal charges have been filed against any suspects.
Łukasz Wawrzyniak, spokesperson for the Regional Prosecutor's Office in Poznań, described the scope of the ongoing investigative measures.
The proceedings are at an early stage, and actions taken in its course concern the possibility of committing an offense under Article 267 Paragraph 1 of the Penal Code. No charges have been presented to anyone. At this stage of the case, due to the interests and secrecy of the proceedings, the prosecutor's office is not providing information on the findings made and planned activities. I can only add that the current activities of investigators are aimed at establishing the mechanism of breaking and bypassing security measures, which will allow further actions to be taken.
Compromised third-party account and extortion attempt
The security incident began in early August 2026, when unauthorized activity was detected within the technical systems that facilitate communication between the franchisor and individual franchisees. Żabka's press office stated that the perpetrators gained entry by compromising an account belonging to an external service provider. Company security teams disconnected the account immediately upon detection to halt unauthorized movement across the network. The retailer then submitted official breach notifications to its internal Data Protection Officer, the President of the Personal Data Protection Office (UODO), and specialized law enforcement units. Shortly after the intrusion, the perpetrators sent electronic messages to media outlets and partner companies before posting the stolen data for sale on a cybercrime forum for an asking price of 5,000 euros.
- Żabka detects unauthorized access via an external service provider account and reports the incident to UODO.
- Attackers offer 541,000 internal employee and contractor records on a cybercrime forum for 5,000 euros.
- The Poznan-Wilda District Prosecutor's Office opens an investigation under Article 267 of the Penal Code.
Technical scope and internal Jira records
Sample files published alongside the sales listing indicated that the attackers accessed Żabka's internal Jira environment, which the company uses for technical task ticketing and project management. Data provided by the attackers indicated that the exfiltrated files contained 541,000 records featuring names, email addresses, and system usernames belonging to company employees and business partners. The compromised materials also reportedly included internal project documentation, source code repositories, and access credentials. Cybersecurity monitoring portal Niebezpiecznik noted that the breach occurred shortly after the public announcement of plans for an acquisition of Żabka by a Canadian company.
Assessment of consumer and retail impact
While initial reports indicated that credentials for some partner accounts and potentially limited customer data might have been exposed, government and company officials emphasized the isolation of core consumer systems. Krzysztof Gawkowski, Poland's Deputy Prime Minister and Minister of Digital Affairs, stated that the intrusion did not compromise personal information from the Żappka mobile application or any financial transaction records. Operational systems governing store checkouts and franchise logistics continued normal functioning throughout the incident without disruption. Prosecutors and digital forensics specialists continue to evaluate the technical evidence to verify whether additional systems were affected during the intrusion.


