2026-08-10 · view entry permalink →
Żabka confirms an external service-provider account reached its ticketing system — the claimed pivot from Jira into source control and production is the seller's assertion, not the company's
Żabka has confirmed a compromise in a written statement its press office gave to Polish outlets, reproduced in near-identical wording by the outlets cited here. The confirmed facts are narrow and worth separating carefully from everything else in circulation. The company detected unauthorized access to selected technical resources supporting information exchange between franchisor and franchisees at the end of the preceding week; the access occurred "przy wykorzystaniu konta zewnętrznego dostawcy usług" — through the use of an external service provider's account — and was detected and immediately blocked under existing security procedures (Niebezpiecznik, 2026-08-03). On scope, Żabka says only that "zgodnie z naszą obecną wiedzą sprawca uzyskał dostęp do systemu kolejkowania zgłoszeń" — to its current knowledge the perpetrator gained access to the ticketing system. It states that transaction data, consumer services and the confidentiality of its loyalty-app data are unaffected, and that it has referred the matter to its own data-protection officer, to the Polish data-protection authority and to specialised law-enforcement bodies, with CERT Polska also notified (RMF FM, 2026-08-04). It declines to name the supplier or comment on the perpetrator.
Everything beyond that is claim. A seller on a criminal forum listed a data package on 2026-08-02, and Niebezpiecznik's itemised breakdown of that listing is prefaced explicitly as conditional on believing the attacker — hundreds of thousands of Jira issues across dozens of projects, service-desk tickets referencing internal retail and ERP systems, source code and infrastructure-as-code from a large number of repositories, and, claimed separately, live production material including a reused access token, message-broker and database credentials, and cloud infrastructure mapping. The mechanism connecting the two halves is not a forensic finding either: the outlet's own words are "Zgadujemy, że atakujący wykorzystał umieszczone w JIRZE informacje takie jak tokeny/hasła/konta testowe aby dostać się do kolejnych systemów" — we guess that the attacker used tokens, passwords or test accounts placed in Jira to reach further systems (Niebezpiecznik, 2026-08-03).
That distinction is the entry's reason for existing, and it cuts in a useful direction rather than a dismissive one. The confirmed half — a third-party account reaching an internal ticketing system — is a shape every public administration running an outsourced service desk shares, and it is confirmed by the victim. The unconfirmed half is a hypothesis about what ticketing systems contain, and it is a hypothesis defenders can test on their own estate today without waiting for anyone's forensics.
Do nieautoryzowanego dostępu doszło przy wykorzystaniu konta zewnętrznego dostawcy usług.
Zgodnie z naszą obecną wiedzą sprawca uzyskał dostęp do systemu kolejkowania zgłoszeń.
Zgadujemy, że atakujący wykorzystał umieszczone w JIRZE informacje takie jak tokeny/hasła/konta testowe aby dostać się do kolejnych systemów.