Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
Alleged Żabka Polska Breach (TL-2026-1834) is a high-severity data breach, first published 2026-08-03. It has no confirmed attribution, affects Żabka Polska (internal) Nowa Kasa point-of-sale platform, maps to 18 MITRE ATT&CK techniques (T1074, T1078, T1087), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1834
- Threat ID
- TL-2026-1834
- Severity
- HIGH
- Status
- ACTIVE
- Category
- DATA_BREACH
- First published
- 2026-08-03
- Last reviewed
- 2026-08-03
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- retail, convenience retail, ecommerce, franchise operations
- Target regions
- poland, Central and Eastern Europe, Europe
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Alleged Żabka Polska Breach
Malware and tooling: Atlassian Jira, Cloudflare, GitLab, MongoDB, SAP ERP
A forum account created 2026-08-02 and used only once claims to be selling a full data dump from Żabka Polska — Poland's largest convenience-store franchise (11,000+ locations) — for €5,000: exactly 541,463 Jira issues, 229,734 IT service-desk tickets, source code from 89 GitLab repositories, Cloudflare API keys, a MongoDB admin password, and messaging-broker credentials, including one reusable 62-character GitLab access token embedded across all 89 repo clone URLs. Third-party reviewer Ransomnews confirmed the headline record counts as exact matches, though secondary claims (35,206 GDPR-reference records, ~4,000 bank-account mentions) largely did not surface in the reviewed samples, and Żabka has issued no public confirmation.
How Alleged Żabka Polska Breach works
On 2026-08-02, a brand-new account on an underground cybercrime forum posted a single listing — 14 minutes after registration and with zero prior trading history — offering a purported full data dump from Żabka Polska for €5,000. Żabka Polska is the franchise-operating subsidiary of publicly traded Żabka Group, Poland's largest convenience-store network with more than 11,000 locations; notably, the listing appeared just two days after Alimentation Couche-Tard publicly announced a PLN 32.62 billion (~€7.56B/US$8.6B) agreement to acquire a controlling stake in Żabka Group (2026-07-31), a timing coincidence that raises the possibility of deliberate extortion or reputational-pressure leverage tied to the pending tender offer, though this motive is not confirmed by any source.
The claimed dump spans internal collaboration and DevOps tooling rather than customer-facing systems: exactly 541,463 Jira issues and 229,734 IT service-desk tickets, plus source code from 89 GitLab repositories. Reporting further details the repository architecture: the leaked estate includes the internal cs-market platform, comprising 44 DevOps repositories, 26 backend services, 7 frontend applications, and an API gateway — giving a buyer not just code but a structural blueprint of how Żabka's retail platform is decomposed and deployed. Most significantly, the seller claims a single 62-character GitLab personal access token was embedded across all 89 repository clone URLs — a credential-reuse pattern that, if the token is still valid, would grant uniform access to Żabka's entire disclosed source-code estate rather than requiring per-repository compromise. The same repositories reportedly contain hardcoded Cloudflare API keys, a MongoDB administrative password, and messaging-broker credentials within infrastructure-as-code files — a textbook case of CWE-798 (Use of Hard-Coded Credentials) at organizational scale.
Leaked Jira/service-desk tickets reportedly reference Żabka's internal technology stack by name: the Nowa Kasa point-of-sale platform, the Cyberstore and zMarket platforms, SAP ERP, and a Lotto (lottery) integration, plus IT vendors Accenture, Netguru, and BlueSoft among more than 17 additional third parties named across the tickets — giving any buyer a de facto architecture map of Żabka's retail and back-office technology estate, and its outsourced-development supply chain, even before touching the source code itself.
Independent verification is partial. Ransomnews reviewed sample archives and confirmed the headline counts (541,463 Jira issues; 229,734 service-desk tickets) as exact matches to the seller's claims, lending strong credibility to the listing's scale. However, two more precise-sounding secondary claims — 35,206 GDPR-reference records and roughly 4,000 bank-account mentions within the dump — largely failed to surface in the reviewed samples, tempering confidence in the listing's completeness or accuracy beyond the core Jira/service-desk/GitLab figures. Żabka has not issued a public statement confirming or denying a breach as of this writing. Poland's RODO (the national GDPR implementation) requires a data controller to notify the national supervisory authority within 72 hours of becoming aware of a qualifying breach; absent public confirmation, it is unclear whether that regulatory clock has started. The threat actor's identity, initial access vector, and dwell time remain unknown; the forum account's brand-new, single-use, zero-history profile is consistent with a burner/sock-puppet account created specifically to monetize already-stolen data rather than an established data-broker persona. Ticket timestamps reportedly suggest the underlying data was assembled before the Couche-Tard tender offer became public, which argues against the listing being crafted purely in reaction to the acquisition news, even though the two-day proximity remains a notable coincidence.
Even unconfirmed, the exposure pattern described — a reusable high-privilege GitLab token, cloud API keys, and a database admin password all embedded in source code shared across dozens of repositories — represents a severe supply-chain and downstream-compromise risk: any buyer with a working token gains read (and potentially write) access to Żabka's proprietary retail, POS, and ERP-integration codebases, from which further credentials, business logic, or injectable code paths could be harvested for follow-on attacks against Żabka's franchise and POS infrastructure.
MITRE ATT&CK techniques used in TL-2026-1834
Collection
T1074 Data Staged; T1119 Automated Collection; T1213 Data from Information Repositories; T1560 Archive Collected Data
Initial Access
T1078 Valid Accounts; T1195 Supply Chain Compromise; T1199 Trusted Relationship
Persistence
Privilege Escalation
Defense Evasion
Discovery
T1087 Account Discovery; T1619 Cloud Storage Object Discovery
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
Lateral Movement
T1550 Use Alternate Authentication Material
Exfiltration
T1567 Exfiltration Over Web Service
Reconnaissance
T1591 Gather Victim Org Information; T1592 Gather Victim Host Information; T1594 Search Victim-Owned Websites
Resource Development
Impact
Affected products and versions in Alleged Żabka Polska Breach
- Żabka Polska (internal) — Nowa Kasa point-of-sale platform
Vulnerable versions: not disclosed in source reporting - Żabka Polska (internal) — Cyberstore platform
Vulnerable versions: not disclosed in source reporting - Żabka Polska (internal) — zMarket platform
Vulnerable versions: not disclosed in source reporting - Atlassian — Jira (issue tracker instance used by Żabka Polska)
Vulnerable versions: not disclosed in source reporting - GitLab Inc. — GitLab (89 self-hosted or Group-hosted repositories)
Vulnerable versions: not disclosed in source reporting - MongoDB Inc. — MongoDB (administrative-level database instance)
Vulnerable versions: not disclosed in source reporting - Cloudflare Inc. — Cloudflare account API
Vulnerable versions: not disclosed in source reporting - SAP SE — SAP ERP (integration referenced in leaked tickets)
Vulnerable versions: not disclosed in source reporting
Remediation for Alleged Żabka Polska Breach
Patches
- Not applicable — this is an alleged credential/data-exposure incident, not a software vulnerability; no vendor patch exists
Immediate actions
- Treat the reported 62-character GitLab access token as compromised and revoke/rotate it immediately across all 89 affected repositories, regardless of breach confirmation status
- Rotate all Cloudflare API keys tied to Żabka's account and review Cloudflare audit logs for unauthorized DNS/WAF/CDN configuration changes since the token's creation date
- Rotate the exposed MongoDB administrative password and any dependent service-account credentials; audit MongoDB access logs for anomalous admin-level connections
- Rotate all messaging-broker credentials referenced in the leaked infrastructure code
- Audit GitLab, Jira, and IT service-desk access/export logs for anomalous bulk-read or bulk-export activity consistent with the claimed record volumes
- Notify and coordinate with named third-party IT vendors (Accenture, Netguru, BlueSoft) referenced in the leaked tickets, since their access/credentials may also be implicated
Workarounds
- Enforce MFA and IP allow-listing on the Cloudflare account console and MongoDB administrative interfaces
- Restrict and monitor Jira/GitLab bulk-export capabilities for anomalous large-scale data pulls
- Assume all credentials appearing anywhere in the 89 GitLab repositories are compromised pending full rotation, not just the specifically named ones
Longer-term hardening
- Deploy automated secret-scanning (e.g., GitLab native secret detection, gitleaks, trufflehog) in CI/CD pipelines and pre-commit hooks to block hardcoded credentials before merge
- Replace long-lived, broadly-scoped personal access tokens with short-lived, narrowly-scoped, per-repository tokens or OIDC-based CI credentials
- Migrate infrastructure secrets (Cloudflare keys, database passwords, broker credentials) out of source control and into a dedicated secrets manager/vault with audited access
- Engage a DFIR firm to independently confirm or refute the breach's scope and validate whether any leaked credentials remain live
- Review and tighten third-party/vendor access scoping (Accenture, Netguru, BlueSoft) under least-privilege principles for Jira, GitLab, and IT service-desk systems
Weaknesses (CWE) in Alleged Żabka Polska Breach
CWE-798, CWE-522
Timeline of Alleged Żabka Polska Breach
- Alimentation Couche-Tard publicly announces a PLN 32.62 billion (~US$8.6B) agreement to acquire a controlling stake in Żabka Group and launches a voluntary tender offer — the concurrent M&A context is cited as a possible factor in the breach listing's timing, though not confirmed as a motive.
- Analysis of the leaked tickets identifies more than 17 additional third-party vendors named alongside Accenture, Netguru, and BlueSoft, widening the scope of implicated supply-chain relationships.
- Reporting details that the 89 leaked GitLab repositories include the internal 'cs-market' platform, comprising 44 DevOps repositories, 26 backend services, 7 frontend applications, and an API gateway.
- Ransomnews confirms the seller's headline figures precisely as 541,463 Jira issues and 229,734 IT service-desk tickets, matching the reviewed sample archives exactly rather than merely approximating them.
- Secondary claims made by the seller — including references to GDPR-related content and bank-account data within the dump — largely fail to surface in the samples reviewed by Ransomnews, limiting confidence in the listing's completeness.
- Independent reviewer Ransomnews examines sample archives from the listing and finds the seller's headline record counts (Jira and service-desk totals) internally consistent with the claims.
- The same account posts a single listing 14 minutes after registration, offering an alleged full Żabka Polska data dump (Jira, IT service-desk tickets, 89 GitLab repositories, Cloudflare/MongoDB/broker credentials) for €5,000.
- A previously unseen account is registered on an unnamed underground cybercrime forum, with no prior posting or trading history.
- Coverage notes that Poland's RODO (GDPR implementation) obligates a breached controller to notify the national supervisory authority within 72 hours of becoming aware of a qualifying breach — a compliance question left open by Żabka's lack of public acknowledgment.
- Security Affairs publishes a report summarizing the alleged breach, the seller's claims, and Ransomnews' partial corroboration.
- As of this report, Żabka Polska has issued no public statement confirming or denying the alleged breach.
Sources cited for Alleged Żabka Polska Breach
- Alleged Żabka breach exposes Jira data, source code, and API keys
- Alimentation Couche-Tard Announces Agreement to Acquire Controlling Stake in Żabka Group and Launches Voluntary Tender Offer (corporate release)
- Alimentation Couche-Tard Announces Agreement to Acquire Controlling Stake in Żabka Group and Launches Voluntary Tender Offer
- Alimentation Couche-Tard Announces Agreement to Acquire Controlling Stake in Żabka Group and Launches Voluntary Tender Offer
- Couche-Tard agrees Żabka acquisition in 32.62bn-zloty deal
- Alimentation Couche-Tard Announces Agreement to Acquire Controlling Stake in Żabka Group and Launches Voluntary Tender Offer (Żabka Group)
- Alimentation Couche-Tard Announces Agreement to Acquire Controlling Stake in Żabka Group and Launches Voluntary Tender Offer (CVC)
Threats related to Alleged Żabka Polska Breach
- Chick-fil-A Confirms Data Breach After Credential Stuffing Attack Exposes Customer Personal and Payment Data
- OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
- Coordinated GitHub API Enumeration and Access Token Abuse Campaign (Ghost Accounts + Compromised PAT/OAuth Tokens)
- SplitVPN (formerly NotVPN) Breach Exposes 58M Connection Logs, 23.4M User Records Despite 'No Logs' Claims
- Threat Actor 'TheHatman' Claims Theft of 3.6M+ Azure/Entra Tenant Employee Records from McDonald's, Gap, Vodafone, TCS, and Six Others via Password Spray/MFA Fatigue; TCS and Gap Dispute the Claims
- Alleged Starbucks Data Breach — Threat Actor 'anes2010' Claims 176M Customer Records for Sale on Cybercrime Forum
Detection coverage for TL-2026-1834
As of 2026-08-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1834 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.