ctipilot.ch

Zabka supplier-account ticketing-system intrusion

incident · incident:zabka-supplier-account-jira-gitlab-secrets-2026-07

Unauthorised access at Żabka, Poland's largest convenience-store franchise chain, confirmed by the company at the start of August 2026: the access came through an external service provider's account and, to Żabka's stated current knowledge, reached the ticketing system; it was detected and immediately blocked, with the data-protection regulator, law enforcement and CERT Polska notified. A criminal-forum seller separately claimed a far larger scope reaching source-code repositories and production infrastructure — a claim the reporting outlets explicitly frame as the attacker's own and unverified (Niebezpiecznik, Sekurak, 2026-08-03).

Aliases: Żabka Jira incident

Coverage timeline
1
first 2026-08-10 → last 2026-08-10
Peak priority
notable
1 notable
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/zabka-supplier-account-jira-access-confirmed · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/zabka-supplier-account-jira-access-confirmed · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/zabka-supplier-account-jira-access-confirmed · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-10/zabka-supplier-account-jira-access-confirmed · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-10/zabka-supplier-account-jira-access-confirmed · ATT&CK page ↗

Story timeline

  1. 2026-08-10Żabka confirms an external service-provider account reached its ticketing system — the claimed pivot from Jira into source control and production is the seller's assertion, not the company's
    active-threatsA supplier account reached Jira at a Polish convenience-store chain; the interesting part of the story is the part nobody has confirmed

Where this entity is cited

  • active-threats1

Source distribution

  • niebezpiecznik.pl1 (33%)
  • rmf.fm1 (33%)
  • sekurak.pl1 (33%)

explore in graph

Entries about Zabka supplier-account ticketing-system intrusion (1)

2026-08-10 · view entry permalink →

NOTABLENATOB2

Żabka confirms an external service-provider account reached its ticketing system — the claimed pivot from Jira into source control and production is the seller's assertion, not the company's

Żabka has confirmed a compromise in a written statement its press office gave to Polish outlets, reproduced in near-identical wording by the outlets cited here. The confirmed facts are narrow and worth separating carefully from everything else in circulation. The company detected unauthorized access to selected technical resources supporting information exchange between franchisor and franchisees at the end of the preceding week; the access occurred "przy wykorzystaniu konta zewnętrznego dostawcy usług" — through the use of an external service provider's account — and was detected and immediately blocked under existing security procedures (Niebezpiecznik, 2026-08-03). On scope, Żabka says only that "zgodnie z naszą obecną wiedzą sprawca uzyskał dostęp do systemu kolejkowania zgłoszeń" — to its current knowledge the perpetrator gained access to the ticketing system. It states that transaction data, consumer services and the confidentiality of its loyalty-app data are unaffected, and that it has referred the matter to its own data-protection officer, to the Polish data-protection authority and to specialised law-enforcement bodies, with CERT Polska also notified (RMF FM, 2026-08-04). It declines to name the supplier or comment on the perpetrator.

Everything beyond that is claim. A seller on a criminal forum listed a data package on 2026-08-02, and Niebezpiecznik's itemised breakdown of that listing is prefaced explicitly as conditional on believing the attacker — hundreds of thousands of Jira issues across dozens of projects, service-desk tickets referencing internal retail and ERP systems, source code and infrastructure-as-code from a large number of repositories, and, claimed separately, live production material including a reused access token, message-broker and database credentials, and cloud infrastructure mapping. The mechanism connecting the two halves is not a forensic finding either: the outlet's own words are "Zgadujemy, że atakujący wykorzystał umieszczone w JIRZE informacje takie jak tokeny/hasła/konta testowe aby dostać się do kolejnych systemów" — we guess that the attacker used tokens, passwords or test accounts placed in Jira to reach further systems (Niebezpiecznik, 2026-08-03).

That distinction is the entry's reason for existing, and it cuts in a useful direction rather than a dismissive one. The confirmed half — a third-party account reaching an internal ticketing system — is a shape every public administration running an outsourced service desk shares, and it is confirmed by the victim. The unconfirmed half is a hypothesis about what ticketing systems contain, and it is a hypothesis defenders can test on their own estate today without waiting for anyone's forensics.

Do nieautoryzowanego dostępu doszło przy wykorzystaniu konta zewnętrznego dostawcy usług.

Zgodnie z naszą obecną wiedzą sprawca uzyskał dostęp do systemu kolejkowania zgłoszeń.

Zgadujemy, że atakujący wykorzystał umieszczone w JIRZE informacje takie jak tokeny/hasła/konta testowe aby dostać się do kolejnych systemów.

Niebezpiecznik 2026-08-03
incident10 Aug 04:52Zmulti-sourceOpen finding ↗