A hacked vendor account let attackers into Żabka's internal systems for days before anyone noticed; the retailer confirmed the breach on 4 August after the data went up for sale.
Why It Matters
The attackers did not break Żabka's own defences. They used a compromised login belonging to an external service provider, then walked out with roughly 541,000 internal project records, source code from dozens of repositories, and production credentials. Most 30-150 person firms hand the same kind of standing access to an IT provider, accountant, or scheduling app, often with no expiry date and no one checking whether it is still in use.
What To Do About It
List every external vendor, accountant, or IT contractor with a standing login into your Microsoft 365 tenant, CRM, or project tools, and check two things this week: does the account still need access, and does it have MFA enabled. An old supplier login is the easiest door into a company that never touched the breach itself.
Related Signals
KSeF carries no administrative penalties until 1 January 2027, but the tax code's separate criminal-fiscal liability for false or missing invoices already applies in full.
5 Aug 2026Polish companies caught by the NIS2 cybersecurity law have until 3 October 2026 to self-identify and register in the national registry, or face a fine before any incident even happens.
5 Aug 2026Poland's grid reform lets a battery share one connection point with solar or wind without counting as a second source, reopening capacity that developers were refused before.
4 Aug 2026