Breached through a supplier's account: the Żabka incident and NIS2 supply chain security
- Aug 5
- 3 min read

On 2 August, a listing appeared on a criminal forum: internal data from the Polish convenience store chain Żabka, priced at €5,000. The account that posted it had been created that same afternoon, fourteen minutes earlier. Listings like this appear every week and most are bluffs. This one was different - a day later, Żabka confirmed an incident.
As quoted by Polish media, Żabka confirmed it had detected unauthorised access to part of its technical resources, and named how that access was obtained: through an external service provider's account. Not an unknown flaw in software, not a deceived employee - an active contractor login. That is what makes this an incident about NIS2 supply chain security: not what you buy from your suppliers, but what people who do not work for you can do inside your systems.
What the company confirmed, and what it did not

According to the same statement, the access was detected and blocked immediately, and the matter was reported to the company's data protection officer, to Poland's data protection authority (UODO, the Polish equivalent of Lithuania's State Data Protection Inspectorate) and to law enforcement. The company says payments, consumer app data and store operations were unaffected.
What the company did not confirm is everything the seller advertises: internal tickets, code repositories, contractor staff records. For now those remain the claims of an anonymous seller.
Why this is not a Polish problem: NIS2 supply chain security in Lithuanian law
Count who has a login to your systems from outside today. Your accounting software vendor. Whoever maintains your website or online store. Your IT support contractor. The integrator who was given remote access three years ago for a single deployment - access that still works, because nobody removed it, or more precisely, because nobody knows it exists.
For public sector bodies in Lithuania, that list is usually longer than in the private sector. Almost all IT maintenance is procured externally, contracts change every few years, and accounts from each previous supplier stay behind.
This is not just a housekeeping question. Lithuania's Cybersecurity Law (KSĮ), which transposes the EU NIS2 directive, sets out the requirement in Article 14(5)(5): supply chain security, including aspects of the relationship between each entity and its direct suppliers and service providers. Point 12 of the same paragraph goes further and is unusually specific - entities must have a policy governing how access rights are granted and managed for users, administrators, suppliers and their subcontractors. If you are not sure whether the law applies to your Lithuanian entity at all, check yourself against three numbers.
One key opened every door
Researchers at Ransomnews, reviewing the sample the seller published, noticed one detail: the same single access token appears in all 89 code repository dumps. A master key to the whole building instead of a separate key for each room - convenient right up until it is not yours.
That is a researcher's finding from a small sample, not information the company confirmed. But the question it raises applies to any organisation: how many doors does one of your supplier accounts open?
How many doors does one of your supplier accounts open?
Three questions worth asking this week
Who from outside has access to our systems today - and is that list written down anywhere? A bad answer sounds like "well, IT more or less knows." A list that does not exist on paper does not exist.
When did we last remove a supplier's account after a contract ended? A bad answer is silence. The project finishes, the invoice is paid, the account stays. In public procurement, it is worth checking whether revoking access is even a contractual condition.
Do supplier logins require multi-factor authentication, and can we see when they are used? A bad answer: "they have their own security policy." They may well do. But the incident will be yours.
If there is no answer to even one of these - that is not a reproach, but a map of where you are now.
€5,000 for a key
Internal data from a chain running thousands of stores was priced below a decent used car. That figure says nothing about what the data is worth, but it does show how cheap access can be when nobody has reviewed it.
Reviewing access rights is one of those jobs that never looks urgent until it suddenly becomes urgent, or overdue. It sits close to both the work of a CISO and to continuous monitoring. If you would like to start with the simple question of who holds your access keys - let's talk.


