Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000 — Threadlinqs Intelligence
As of 2026-08-03, Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000 is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1834 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
A forum account created 2026-08-02 and used only once claims to be selling a full data dump from Żabka Polska — Poland's largest convenience-store franchise (11,000+ locations) — for €5,000: exactly
On 2026-08-02, a brand-new account on an underground cybercrime forum posted a single listing — 14 minutes after registration and with zero prior trading history — offering a purported full data dump from Żabka Polska for €5,000. Żabka Polska is the franchise-operating subsidiary of publicly traded Żabka Group, Poland's largest convenience-store network with more than 11,000 locations; notably, the listing appeared just two days after Alimentation Couche-Tard publicly announced a PLN 32.62 billion (~€7.56B/US$8.6B) agreement to acquire a controlling stake in Żabka Group (2026-07-31), a timing coincidence that raises the possibility of deliberate extortion or reputational-pressure leverage tied to the pending tender offer, though this motive is not confirmed by any source.
The claimed dump spans internal collaboration and DevOps tooling rather than customer-facing systems: exactly 541,463 Jira issues and 229,734 IT service-desk tickets, plus source code from 89 GitLab repositories. Reporting further details the repository architecture: the leaked estate includes the internal cs-market platform, comprising 44 DevOps repositories, 26 backend services, 7 frontend applications, and an API gateway — giving a buyer not just code but a structural blueprint of how Żabka's retail platform is decomposed and deployed. Most significantly, the seller claims a single 62-character GitLab personal access token was embedded across all 89 repository clone URLs — a credential-reuse pattern that, if the token is still valid, would grant uniform access to Żabka's entire disclosed source-code estate rather than requiring per-repository compromise. The same repositories reportedly contain hardcoded Cloudflare API keys, a MongoDB administrative password, and messaging-broker credentials within infrastructure-as-code files — a textbook case of CWE-798 (Use of Hard-Coded Credentials) at organizational scale.
Leaked Jira/service-desk tickets reportedly reference Żabka's internal technology stack by name: the Nowa Kasa point-of-sale platform, the Cyberstore and zMarket platforms, SAP ERP, and a Lotto (lottery) integration, plus IT vendors Accenture, Netguru, and BlueSoft among more than 17 additional third parties named across the tickets — giving any buyer a de facto architecture map of Żabka's retail and back-office technology estate, and its outsourced-development supply chain, even before touching the source code itself.
Independent verification is partial. Ransomnews reviewed sample archives and confirmed the headline counts (541,463 Jira issues; 229,734 service-desk tickets) as exact matches to the seller's claims, lending strong credibility to the listing's scale. However, two more precise-sounding secondary claims — 35,206 GDPR-reference records and roughly 4,000 bank-account mentions within the dump — largely failed to surface in the reviewed samples, tempering confidence in the listing's completeness or accuracy beyond the core Jira/service-desk/GitLab figures. Żabka has not issued a public statement confirming or denying a breach as of this writing. Poland's RODO (the national GDPR implementation) requires a data controller to notify the national supervisory authority within 72 hours of becoming aware of a qualifying breach; absent public confirmation, it is unclear whether that regulatory clock has started. The threat actor's identity, initial access vector, and dwell time remain unknown; the forum account's brand-new, single-use, zero-history profile is consistent with a burner/sock-puppet account created specifically to monetize already-stolen data rather than an established data-broker persona. Ticket timestamps reportedly suggest the underlying data was assembled before the Couche-Tard tender offer became public, which argues against the listing being crafted purely in reaction to the acquisition news, even though the two-day proximity remains a notable coincidence.
Even unconfirmed, the exposure pattern described — a reusable high-pri
Weaknesses (CWE)
CWE-798, CWE-522
Target sectors: retail, convenience retail, ecommerce, franchise operations
Target regions: poland, Central and Eastern Europe, Europe
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1592, T1650, T1199, T1195, T1078, T1552, T1528, T1213, T1213, T1119