Żabka confirms an external service-provider account reached its ticketing system — the claimed pivot from Jira into source control and production is the seller's assertion, not the company's
Żabka has confirmed a compromise in a written statement its press office gave to Polish outlets, reproduced in near-identical wording by the outlets cited here. The confirmed facts are narrow and worth separating carefully from everything else in circulation. The company detected unauthorized access to selected technical resources supporting information exchange between franchisor and franchisees at the end of the preceding week; the access occurred "przy wykorzystaniu konta zewnętrznego dostawcy usług" — through the use of an external service provider's account — and was detected and immediately blocked under existing security procedures (Niebezpiecznik, 2026-08-03). On scope, Żabka says only that "zgodnie z naszą obecną wiedzą sprawca uzyskał dostęp do systemu kolejkowania zgłoszeń" — to its current knowledge the perpetrator gained access to the ticketing system. It states that transaction data, consumer services and the confidentiality of its loyalty-app data are unaffected, and that it has referred the matter to its own data-protection officer, to the Polish data-protection authority and to specialised law-enforcement bodies, with CERT Polska also notified (RMF FM, 2026-08-04). It declines to name the supplier or comment on the perpetrator.
Everything beyond that is claim. A seller on a criminal forum listed a data package on 2026-08-02, and Niebezpiecznik's itemised breakdown of that listing is prefaced explicitly as conditional on believing the attacker — hundreds of thousands of Jira issues across dozens of projects, service-desk tickets referencing internal retail and ERP systems, source code and infrastructure-as-code from a large number of repositories, and, claimed separately, live production material including a reused access token, message-broker and database credentials, and cloud infrastructure mapping. The mechanism connecting the two halves is not a forensic finding either: the outlet's own words are "Zgadujemy, że atakujący wykorzystał umieszczone w JIRZE informacje takie jak tokeny/hasła/konta testowe aby dostać się do kolejnych systemów" — we guess that the attacker used tokens, passwords or test accounts placed in Jira to reach further systems (Niebezpiecznik, 2026-08-03).
That distinction is the entry's reason for existing, and it cuts in a useful direction rather than a dismissive one. The confirmed half — a third-party account reaching an internal ticketing system — is a shape every public administration running an outsourced service desk shares, and it is confirmed by the victim. The unconfirmed half is a hypothesis about what ticketing systems contain, and it is a hypothesis defenders can test on their own estate today without waiting for anyone's forensics.
Do nieautoryzowanego dostępu doszło przy wykorzystaniu konta zewnętrznego dostawcy usług.
Zgodnie z naszą obecną wiedzą sprawca uzyskał dostęp do systemu kolejkowania zgłoszeń.
Zgadujemy, że atakujący wykorzystał umieszczone w JIRZE informacje takie jak tokeny/hasła/konta testowe aby dostać się do kolejnych systemów.
ATT&CK mapping
2 techniques mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Persistence TA0003
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Privilege Escalation TA0004
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Stealth TA0005
T1078Valid Accounts
Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.
Collection TA0009
T1213Data from Information Repositories
Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.