A hacked vendor account let attackers into Żabka's internal systems for days before anyone noticed; the retailer confirmed the breach on 4 August after the data went up for sale.
Why It Matters
The attackers did not break Żabka's own defences. They used a compromised login belonging to an external service provider, then walked out with roughly 541,000 internal project records, source code from dozens of repositories, and production credentials. Most 30-150 person firms hand the same kind of standing access to an IT provider, accountant, or scheduling app, often with no expiry date and no one checking whether it is still in use.
What To Do About It
List every external vendor, accountant, or IT contractor with a standing login into your Microsoft 365 tenant, CRM, or project tools, and check two things this week: does the account still need access, and does it have MFA enabled. An old supplier login is the easiest door into a company that never touched the breach itself.
Related Signals
Od 7 września 2026 operatorzy sieci dostają prawo zdalnie ograniczać moc mikroinstalacji 0,8-50 kW albo je odłączać, jeśli zagrażają sieci albo właściciel nie zainstaluje wymaganego urządzenia sterującego.
25 Aug 2026A partir de 1 de outubro de 2026 entra em vigor o Decreto-Lei 108/2026: a comunicação prévia deixa de ter fase de saneamento e a obra pode arrancar logo após o pagamento das taxas.
25 Aug 2026Od 7 stycznia 2026 obiekty do 200 m² na dwóch kondygnacjach powstają na zgłoszenie, nie pozwolenie na budowę, a nadzór budowlany dostał nowe narzędzie: 60 dni na poprawki zamiast wstrzymania robót.
25 Aug 2026