Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000

Alleged Żabka Polska Breach (TL-2026-1834) is a high-severity data breach, first published 2026-08-03. It has no confirmed attribution, affects Żabka Polska (internal) Nowa Kasa point-of-sale platform, maps to 18 MITRE ATT&CK techniques (T1074, T1078, T1087), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1834

Threat ID
TL-2026-1834
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-03
Last reviewed
2026-08-03
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
retail, convenience retail, ecommerce, franchise operations
Target regions
poland, Central and Eastern Europe, Europe
Detection rules
9
Indicators of compromise
27

Malware and tooling in Alleged Żabka Polska Breach

Malware and tooling: Atlassian Jira, Cloudflare, GitLab, MongoDB, SAP ERP

A forum account created 2026-08-02 and used only once claims to be selling a full data dump from Żabka Polska — Poland's largest convenience-store franchise (11,000+ locations) — for €5,000: exactly 541,463 Jira issues, 229,734 IT service-desk tickets, source code from 89 GitLab repositories, Cloudflare API keys, a MongoDB admin password, and messaging-broker credentials, including one reusable 62-character GitLab access token embedded across all 89 repo clone URLs. Third-party reviewer Ransomnews confirmed the headline record counts as exact matches, though secondary claims (35,206 GDPR-reference records, ~4,000 bank-account mentions) largely did not surface in the reviewed samples, and Żabka has issued no public confirmation.

How Alleged Żabka Polska Breach works

On 2026-08-02, a brand-new account on an underground cybercrime forum posted a single listing — 14 minutes after registration and with zero prior trading history — offering a purported full data dump from Żabka Polska for €5,000. Żabka Polska is the franchise-operating subsidiary of publicly traded Żabka Group, Poland's largest convenience-store network with more than 11,000 locations; notably, the listing appeared just two days after Alimentation Couche-Tard publicly announced a PLN 32.62 billion (~€7.56B/US$8.6B) agreement to acquire a controlling stake in Żabka Group (2026-07-31), a timing coincidence that raises the possibility of deliberate extortion or reputational-pressure leverage tied to the pending tender offer, though this motive is not confirmed by any source.

The claimed dump spans internal collaboration and DevOps tooling rather than customer-facing systems: exactly 541,463 Jira issues and 229,734 IT service-desk tickets, plus source code from 89 GitLab repositories. Reporting further details the repository architecture: the leaked estate includes the internal cs-market platform, comprising 44 DevOps repositories, 26 backend services, 7 frontend applications, and an API gateway — giving a buyer not just code but a structural blueprint of how Żabka's retail platform is decomposed and deployed. Most significantly, the seller claims a single 62-character GitLab personal access token was embedded across all 89 repository clone URLs — a credential-reuse pattern that, if the token is still valid, would grant uniform access to Żabka's entire disclosed source-code estate rather than requiring per-repository compromise. The same repositories reportedly contain hardcoded Cloudflare API keys, a MongoDB administrative password, and messaging-broker credentials within infrastructure-as-code files — a textbook case of CWE-798 (Use of Hard-Coded Credentials) at organizational scale.

Leaked Jira/service-desk tickets reportedly reference Żabka's internal technology stack by name: the Nowa Kasa point-of-sale platform, the Cyberstore and zMarket platforms, SAP ERP, and a Lotto (lottery) integration, plus IT vendors Accenture, Netguru, and BlueSoft among more than 17 additional third parties named across the tickets — giving any buyer a de facto architecture map of Żabka's retail and back-office technology estate, and its outsourced-development supply chain, even before touching the source code itself.

Independent verification is partial. Ransomnews reviewed sample archives and confirmed the headline counts (541,463 Jira issues; 229,734 service-desk tickets) as exact matches to the seller's claims, lending strong credibility to the listing's scale. However, two more precise-sounding secondary claims — 35,206 GDPR-reference records and roughly 4,000 bank-account mentions within the dump — largely failed to surface in the reviewed samples, tempering confidence in the listing's completeness or accuracy beyond the core Jira/service-desk/GitLab figures. Żabka has not issued a public statement confirming or denying a breach as of this writing. Poland's RODO (the national GDPR implementation) requires a data controller to notify the national supervisory authority within 72 hours of becoming aware of a qualifying breach; absent public confirmation, it is unclear whether that regulatory clock has started. The threat actor's identity, initial access vector, and dwell time remain unknown; the forum account's brand-new, single-use, zero-history profile is consistent with a burner/sock-puppet account created specifically to monetize already-stolen data rather than an established data-broker persona. Ticket timestamps reportedly suggest the underlying data was assembled before the Couche-Tard tender offer became public, which argues against the listing being crafted purely in reaction to the acquisition news, even though the two-day proximity remains a notable coincidence.

Even unconfirmed, the exposure pattern described — a reusable high-privilege GitLab token, cloud API keys, and a database admin password all embedded in source code shared across dozens of repositories — represents a severe supply-chain and downstream-compromise risk: any buyer with a working token gains read (and potentially write) access to Żabka's proprietary retail, POS, and ERP-integration codebases, from which further credentials, business logic, or injectable code paths could be harvested for follow-on attacks against Żabka's franchise and POS infrastructure.

MITRE ATT&CK techniques used in TL-2026-1834

Collection

T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories; T1560 Archive Collected Data

Initial Access

T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship

Persistence

T1078 Valid Accounts

Privilege Escalation

T1078 Valid Accounts

Defense Evasion

T1078 Valid Accounts

Discovery

T1087 Account Discovery; T1619 Cloud Storage Object Discovery

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

Lateral Movement

T1550 Use Alternate Authentication Material

Exfiltration

T1567 Exfiltration Over Web Service

Reconnaissance

T1591 Gather Victim Org Information; T1592 Gather Victim Host Information; T1594 Search Victim-Owned Websites

Resource Development

T1650 Acquire Access

Impact

T1657 Financial Theft

Affected products and versions in Alleged Żabka Polska Breach

  • Żabka Polska (internal) — Nowa Kasa point-of-sale platform
    Vulnerable versions: not disclosed in source reporting
  • Żabka Polska (internal) — Cyberstore platform
    Vulnerable versions: not disclosed in source reporting
  • Żabka Polska (internal) — zMarket platform
    Vulnerable versions: not disclosed in source reporting
  • Atlassian — Jira (issue tracker instance used by Żabka Polska)
    Vulnerable versions: not disclosed in source reporting
  • GitLab Inc. — GitLab (89 self-hosted or Group-hosted repositories)
    Vulnerable versions: not disclosed in source reporting
  • MongoDB Inc. — MongoDB (administrative-level database instance)
    Vulnerable versions: not disclosed in source reporting
  • Cloudflare Inc. — Cloudflare account API
    Vulnerable versions: not disclosed in source reporting
  • SAP SE — SAP ERP (integration referenced in leaked tickets)
    Vulnerable versions: not disclosed in source reporting

Remediation for Alleged Żabka Polska Breach

Patches

  • Not applicable — this is an alleged credential/data-exposure incident, not a software vulnerability; no vendor patch exists

Immediate actions

  • Treat the reported 62-character GitLab access token as compromised and revoke/rotate it immediately across all 89 affected repositories, regardless of breach confirmation status
  • Rotate all Cloudflare API keys tied to Żabka's account and review Cloudflare audit logs for unauthorized DNS/WAF/CDN configuration changes since the token's creation date
  • Rotate the exposed MongoDB administrative password and any dependent service-account credentials; audit MongoDB access logs for anomalous admin-level connections
  • Rotate all messaging-broker credentials referenced in the leaked infrastructure code
  • Audit GitLab, Jira, and IT service-desk access/export logs for anomalous bulk-read or bulk-export activity consistent with the claimed record volumes
  • Notify and coordinate with named third-party IT vendors (Accenture, Netguru, BlueSoft) referenced in the leaked tickets, since their access/credentials may also be implicated

Workarounds

  • Enforce MFA and IP allow-listing on the Cloudflare account console and MongoDB administrative interfaces
  • Restrict and monitor Jira/GitLab bulk-export capabilities for anomalous large-scale data pulls
  • Assume all credentials appearing anywhere in the 89 GitLab repositories are compromised pending full rotation, not just the specifically named ones

Longer-term hardening

  • Deploy automated secret-scanning (e.g., GitLab native secret detection, gitleaks, trufflehog) in CI/CD pipelines and pre-commit hooks to block hardcoded credentials before merge
  • Replace long-lived, broadly-scoped personal access tokens with short-lived, narrowly-scoped, per-repository tokens or OIDC-based CI credentials
  • Migrate infrastructure secrets (Cloudflare keys, database passwords, broker credentials) out of source control and into a dedicated secrets manager/vault with audited access
  • Engage a DFIR firm to independently confirm or refute the breach's scope and validate whether any leaked credentials remain live
  • Review and tighten third-party/vendor access scoping (Accenture, Netguru, BlueSoft) under least-privilege principles for Jira, GitLab, and IT service-desk systems

Weaknesses (CWE) in Alleged Żabka Polska Breach

CWE-798, CWE-522

Timeline of Alleged Żabka Polska Breach

  • Alimentation Couche-Tard publicly announces a PLN 32.62 billion (~US$8.6B) agreement to acquire a controlling stake in Żabka Group and launches a voluntary tender offer — the concurrent M&A context is cited as a possible factor in the breach listing's timing, though not confirmed as a motive.
  • Analysis of the leaked tickets identifies more than 17 additional third-party vendors named alongside Accenture, Netguru, and BlueSoft, widening the scope of implicated supply-chain relationships.
  • Reporting details that the 89 leaked GitLab repositories include the internal 'cs-market' platform, comprising 44 DevOps repositories, 26 backend services, 7 frontend applications, and an API gateway.
  • Ransomnews confirms the seller's headline figures precisely as 541,463 Jira issues and 229,734 IT service-desk tickets, matching the reviewed sample archives exactly rather than merely approximating them.
  • Secondary claims made by the seller — including references to GDPR-related content and bank-account data within the dump — largely fail to surface in the samples reviewed by Ransomnews, limiting confidence in the listing's completeness.
  • Independent reviewer Ransomnews examines sample archives from the listing and finds the seller's headline record counts (Jira and service-desk totals) internally consistent with the claims.
  • The same account posts a single listing 14 minutes after registration, offering an alleged full Żabka Polska data dump (Jira, IT service-desk tickets, 89 GitLab repositories, Cloudflare/MongoDB/broker credentials) for €5,000.
  • A previously unseen account is registered on an unnamed underground cybercrime forum, with no prior posting or trading history.
  • Coverage notes that Poland's RODO (GDPR implementation) obligates a breached controller to notify the national supervisory authority within 72 hours of becoming aware of a qualifying breach — a compliance question left open by Żabka's lack of public acknowledgment.
  • Security Affairs publishes a report summarizing the alleged breach, the seller's claims, and Ransomnews' partial corroboration.
  • As of this report, Żabka Polska has issued no public statement confirming or denying the alleged breach.

Sources cited for Alleged Żabka Polska Breach

Threats related to Alleged Żabka Polska Breach

Detection coverage for TL-2026-1834

As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1834 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats