A hacked vendor account let attackers into Żabka's internal systems for days before anyone noticed; the retailer confirmed the breach on 4 August after the data went up for sale.
Why It Matters
The attackers did not break Żabka's own defences. They used a compromised login belonging to an external service provider, then walked out with roughly 541,000 internal project records, source code from dozens of repositories, and production credentials. Most 30-150 person firms hand the same kind of standing access to an IT provider, accountant, or scheduling app, often with no expiry date and no one checking whether it is still in use.
What To Do About It
List every external vendor, accountant, or IT contractor with a standing login into your Microsoft 365 tenant, CRM, or project tools, and check two things this week: does the account still need access, and does it have MFA enabled. An old supplier login is the easiest door into a company that never touched the breach itself.