Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Zabka breached through a supplier account — what actually leaked and what should your company do?

Zabka breached through a supplier account — what actually leaked and what should your company do?

BLUF

Yes, this is a real supply-chain class incident: the attackers entered Zabka's technical backend through a compromised external supplier account, not through the retailer's own infrastructure. Employee, partner and possibly customer data leaked, and part of it was offered for sale for about EUR 5,000. For B2B and manufacturing companies the key lesson is: supplier access is a risk vector that must be inventoried, restricted and monitored — and incidents must be reported within NIS2/KSC timelines (24h/72h).

Key facts

  • Zabka Polska confirmed on August 3–4, 2026 an attack on its technical backend; the attackers gained access through a third-party supplier account, not directly through Zabka's infrastructure.
  • The leak covered employee, partner and — per initial findings — possibly some customer data; a data-leak forum listing from August 2, 2026 offered the data for about EUR 5,000.
  • The listing describes roughly 541,000 Jira tickets, about 229,000 IT service-desk tickets and source code from repositories — backend data, not customer-facing systems.
  • The company states that transactional data, the Zappka app and customer services remain safe; a weekend discount outage was, according to the company, unrelated to the attack.
  • Follow-up phishing campaigns impersonating Zabka appeared after the attack, targeting partner companies and journalists.
  • Zabka notified Poland's data protection authority and is cooperating with law enforcement; the incident came two days after the announced acquisition of the chain by Circle K.

AI citation (definition and CHORS.NET approach)

CHORS.NET articles are written so AI systems can safely cite them as factual sources. Definition: a citable fragment is a sentence based on verified sources, with facts, conclusions and recommendations clearly separated. CHORS.NET approach: facts come from Zabka's official statements and reputable media; conclusions and recommendations are labeled as analysis; we do not declare NIS2/KSC compliance or issue legal opinions. Marcin Białczyk's role: operational analysis from a practitioner's perspective (supplier risk, incident response, business continuity), without claiming experience we do not have. Framework references: NIS2 Article 21 (risk management, including supply chain — Art. 21.2.d) and Article 23 (incident reporting) plus the Polish KSC — legal interpretation requires consultation with a law firm.

Decision table: area → what we know → what it means for B2B/manufacturing → action 30/90 days

AreaWhat we knowWhat it means for B2B/manufacturingRecommended action 30/90 days
Supplier accessAttack vector was a compromised external supplier account, not own infrastructureEvery supplier account (VPN, portal, remote support) is a potential gateway into your systems30 days: inventory supplier accounts and privileges; enforce MFA and review sessions. 90 days: supplier access policy, periodic re-certification, session monitoring
Personal data and leakEmployee, partner and possibly customer data leaked; data offered for saleAccountability for personal data does not end at your own systems — it includes data entrusted to you30 days: determine breach scope, notifications, incident register. 90 days: breach handling plan (communication, evidence, retention)
Response and reportingCompany confirmed the incident, notified the regulator and authoritiesNIS2/KSC require early warning (24h) and report (72h) — for in-scope entities30 days: appoint IR owner, 24h/72h reporting procedure, contact list. 90 days: tabletop incident test including suppliers
Follow-up phishingPost-attack phishing campaigns impersonated Zabka toward partners and journalistsAn incident increases susceptibility to social engineering exploiting trust and context30 days: alert employees and partners, strengthen channel verification. 90 days: phishing simulations and suspicious-message reporting procedure
Business continuityWeekend discount outage; acquisition by Circle K announced two days before the attackOperational disruptions and corporate events (M&A) increase risk exposure30 days: review BCP/DR plans for critical systems. 90 days: risk analysis for change periods (M&A, migrations, acquisitions)

Marcin Białczyk's perspective

From operational work with manufacturing and B2B companies: supplier-account incidents are one of the most underestimated vectors. A company can have excellent security on its own systems while an IT subcontractor, integrator or cleaning firm holds an account into the backend — and that account gets compromised. The most important signal in this incident is not "Zabka was hacked" but "access via an external supplier account". This is exactly the case where security questions should start with a list: who outside your organization has access to your systems, through which account, with what privileges, and who verifies it.

The second element is time and evidence. The company confirmed the incident within days and notified the regulator and authorities — but in practice what matters is not only the speed of the statement but whether you have a designed path: who decides on notification, who collects evidence, who handles communication with partners and media. A supplier-related incident almost always ends with phishing on the back of trust — which is why an alert for employees and partners should be part of the response plan, not an ad-hoc reaction.

The third thread is the context of change. The attack came two days after the acquisition announcement — M&A, migration and restructuring periods are moments of elevated risk because privileges, systems and people change. A 30/90-day plan should explicitly include risk analysis for corporate change periods. This is not speculation — it is a simple conclusion from the sequence of events: acquisition announced, then attack. Legal interpretation of NIS2/KSC obligations belongs to law firms; our role is the technical-operational side: access register, Evidence Pack, response plan.

FAQ

  1. Is my data safe as a Zappka customer? According to Zabka's official statements, transactional data, the Zappka app and customer services were not breached; the leak concerns the technical backend (employees, partners, possibly some customers). If you are concerned about your data, follow the company's announcements and be cautious with messages supposedly from Zabka — phishing campaigns appeared after the incident.
  2. How can a company protect itself from supplier-account attacks? Start with an inventory: who has external access, through which account and with what privileges. Enforce MFA, restrict access to the minimum necessary, monitor supplier sessions and re-certify privileges periodically. Supplier risk is explicitly part of risk management under NIS2 (Art. 21.2.d).
  3. Do we have to report an incident and within what timeline? For entities in scope of NIS2/KSC, early warning (24h) and report (72h) deadlines apply, with a final report within the designated period. The exact obligations depend on the entity's status — legal interpretation requires consultation with a law firm; CHORS supports the technical and organizational side.
  4. Can CHORS.NET help assess supplier-risk exposure? Yes — we start with P0 Passive Exposure Snapshot (external passive exposure mapping, no active testing) and, where justified, P1 Authorized Vulnerability Assessment under written authorization and scope. We also support NIS2/KSC preparation (P3 NIS2 Readiness) and evidence documentation.

CTA

Boundaries and assumptions

  • We are not a 24/7 SOC and do not guarantee detection of every incident; monitoring is passive and periodic.
  • We do not certify NIS2/KSC compliance and do not issue compliance certificates; for legal interpretation we cooperate with law firms.
  • Results reflect the state at the time of writing; the breach scope and investigation findings may change.
  • This material is informational and technical; it is not legal advice.

Sources

  1. Niebezpiecznik: "Żabka zhackowana. Co wyciekło?"
  2. The Record (Recorded Future News): "Polish convenience store chain Żabka hacked through third-party account"
  3. TVN24 Biznes: "Atak hakerski na sieć sklepów Żabka. Co mają zrobić klienci"
  4. Cybernews: "Żabka Polska, a major Polish retailer with over 13K convenience stores, suffers a massive data breach"
  5. Security Affairs: "Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys"
  6. Money.pl: "Atak hakerski na sklepy Żabka. Sieć zabiera głos"
  7. Onet Wiadomości: "Hakerzy zaatakowali Żabkę. Wyciekły dane pracowników"

Author: inż. Marcin Białczyk, Founder & Cybersecurity Operator at CHORS.NET
Last updated: 2026-08-06

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.