Security Affairs
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys|Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing|CareCloud Breach Exposes Medical and Financial Data of 345,000|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108|Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION|CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks|Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens|Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic|South Korea Warns of State-Backed Watering Hole Attacks|Google AI Supercharges Chrome Security, Fixing 1,072 Bugs|What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery|Anthropic Finds Claude Breached Real Companies During Security Evaluations|Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys|Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing|CareCloud Breach Exposes Medical and Financial Data of 345,000|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108|Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION|CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks|Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens|Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic|South Korea Warns of State-Backed Watering Hole Attacks|Google AI Supercharges Chrome Security, Fixing 1,072 Bugs|What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery|Anthropic Finds Claude Breached Real Companies During Security Evaluations|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Polska is Poland’s largest convenience store operator […]

Żabka

Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample.

A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska.

Żabka Polska is Poland’s largest convenience store operator and one of the country’s leading retail companies. Founded in 1998, it operates a franchise network of more than 11,000 convenience stores across Poland, serving millions of customers every day.

Ransomnews reviewed the sample archive attached to the listing and found something worth taking seriously: the numbers the seller bragged about mostly check out. Żabka itself hasn’t confirmed anything.

The listing claims roughly 541,000 Jira issues, nearly 230,000 IT service-desk tickets, and source code pulled from 89 GitLab repositories. It names real internal systems too, Żabka’s point-of-sale platform Nowa Kasa, its Cyberstore and zMarket tools, SAP ERP, and a Lotto integration, plus more than 20 outside vendors including Accenture, Netguru, and BlueSoft. Naming actual systems this specific is either confidence or carelessness, and it turned out to work against the seller.

“A data-leak forum account registered on 2 August 2026 advertised an alleged Żabka Polska dataset the same afternoon, asking €5,000. The listing claims roughly 541,000 Jira issues, 229,734 IT service-desk tickets and source code from 89 GitLab repositories. Ransomnews reviewed the sample archive attached to the post.” reads the report published by Ransomnews. “The headline counts are internally consistent, and a single GitLab access token appears in all 89 repository dumps. Żabka Group has not confirmed any breach.”

Ransomnews checked the seller’s own math against the sample files, and most of it held up. Forty-eight Jira exports summed to 541,463 issues, matching the headline claim almost exactly, and the IT service-desk export hit its stated total on the nose. But two of the flashier numbers, 35,206 GDPR references and roughly 4,000 bank account mentions, mostly failed to show up in the sample at all.

“Two numbers failing is not the same as the alleged dataset being fake, and the ones that match are not proof it is real. RODO references and bank details would cluster in HR, legal and finance projects, and those are exactly the projects the 50-issue cap under-samples.” continues the report. “But the seller quoted both figures to five significant digits, and neither survives contact with the evidence they chose to publish. Treat the precise-sounding secondary counts as marketing until somebody sees the full set.”

The part that should actually worry Żabka isn’t the personal data. It’s a single GitLab access token, 62 characters long, embedded in the clone URL of every one of the 89 repository dumps.

“On the seller’s own evidence, then, the whole cs-market platform, 44 devops repositories, 26 backend services, seven frontends, plus the API gateway and tooling, was cloned with a single credential.” constinues the report. “Whoever holds that token holds the codebase. We have not tested it, and we will not: probing a credential found in a criminal listing would be”

That’s not a small claim. One credential, if it’s real and still active, would have cloned Żabka’s entire cs-market platform: 44 devops repositories, 26 backend services, seven frontends, an API gateway, and the tooling around all of it. The repositories also contained live-looking secrets, Cloudflare API keys, a MongoDB admin password, and messaging broker credentials sitting inside infrastructure code.

Timing is the detail that makes this awkward rather than routine. Alimentation Couche-Tard announced a €7.56 billion offer for Żabka Group on July 31, and the leak listing appeared two days later. Ransomnews found no evidence connecting the two events, and the ticket timestamps in the sample suggest the data was pulled together before the acquisition became public, but a leak surfacing mid-diligence is the kind of coincidence a buyer’s lawyers will want explained.

“We have no evidence the two events are connected, and the ticket timestamps in the sample suggest the data was assembled before the bid was public. But an alleged leak that documents a technology estate down to the cluster names, with a reused platform credential in the export, is a question worth asking during diligence on a company with roughly 13,000 stores and 11,000 franchisees.” concludes Ransomnews. “Under RODO, a controller has 72 hours to notify the Polish supervisory authority once it becomes aware of a personal data breach. Whether that duty has been triggered here is for Żabka to determine, and the company has said nothing publicly either way.”

How did a project tracker and some code repositories end up worth stealing in the first place? Almost never through a Jira bug. The dominant pattern since 2024 has been stolen employee logins, usually harvested by infostealer malware, then used to just log in and export everything through the front door. Nothing here proves that’s what happened at Żabka specifically, but it’s the shape everyone in this space has learned to recognize.

The account selling all this has zero trading history and posted the listing fourteen minutes after it was created. That’s not proof the data is fake, but it strips away the usual shortcut of checking a seller’s track record. All anyone has to go on is the sample itself, which is exactly why picking it apart in public was worth doing.

Rotating a token takes five minutes. Finding out it’s been quietly cloning your entire codebase for who knows how long takes considerably longer, and that gap is usually where the real damage happens.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Żabka )