Alleged Żabka Data Breach Exposes Source Code and Jira Data – Veri Sızıntısı

Alleged Żabka Breach Exposes Jira Data and Source Code

Poland's largest convenience store chain, Żabka, is allegedly the victim of a major data breach. Data, including Jira issues, source code, and API keys, has been listed for sale on a forum for €5,000. A single GitLab access token is believed to be at the core of the incident.

A conceptual image showing the Żabka logo in front of a broken padlock icon.

What Happened

Żabka Polska, Poland's largest convenience store operator and a retail giant, is at the center of a significant cybersecurity incident. On August 2, 2026, a newly created account on a cybercrime forum posted a massive dataset for sale for €5,000, claiming it belonged to the company. Founded in 1998, Żabka operates over 11,000 stores across Poland, serving millions of customers daily, making it one of the country's most recognizable brands. This status significantly amplifies the potential impact of the alleged breach.

A review of the sample data by cybersecurity researchers and the Ransomnews platform suggests that the threat actor's claims should be taken seriously. Many of the figures mentioned in the sale listing are consistent with the data found in the shared sample files. This consistency strengthens the possibility that the breach is genuine, although Żabka Polska has not yet issued an official confirmation or denial. The company is currently remaining silent. The sale listing emphasizes that the data contains critical information about the company's internal systems, software development processes, and operational details.

What Data Was Exposed

According to the sale listing, the leaked data package is extensive and contains in-depth information about the company's technological infrastructure. Based on the claims and analysis of the sample data, the exposed information includes:

  • Jira Issues: Approximately 541,000 Jira issues were allegedly exfiltrated. Jira is a platform used by software development teams for project management, bug tracking, and task assignments. The leak of these records could expose the company's software development lifecycle, ongoing projects, known but unpatched security vulnerabilities, and internal communications between developers. A review of 48 Jira export files by Ransomnews confirmed a total of 541,463 issues, almost exactly matching the claim.
  • IT Service Desk Tickets: A precise total of 229,734 IT service-desk tickets were reportedly compromised. These tickets contain details about technical problems experienced by employees, system errors, and help requests. They could reveal valuable information about the company's internal network structure, software in use, hardware inventory, and common system failures. This number was also confirmed to match the sample data exactly.
  • Source Code: One of the most critical components of the leak is the source code allegedly pulled from 89 different GitLab repositories. These repositories are said to belong to core operational systems, including the point-of-sale (POS) platform "Nowa Kasa," e-commerce tools "Cyberstore" and "zMarket," the SAP ERP system, and a Lotto integration. The exposure of source code would allow attackers to easily identify vulnerabilities in these systems and orchestrate more sophisticated attacks in the future.
  • Partner and Internal System Information: The listing mentions the names of more than 20 external partners, including Accenture, Netguru, and BlueSoft. This indicates that the breach could affect not only Żabka but also its relationships and joint projects with its business partners.
  • Unverified Claims: Although the seller claims the data includes 35,206 GDPR references and approximately 4,000 bank account numbers, no evidence supporting these claims was found in the provided sample files. Researchers note that such sensitive data would likely be concentrated in projects related to HR, legal, and finance departments, which may not have been included in the limited sample. However, it is stressed that these figures should be treated as a marketing tactic for now.

How the Attack Happened

The exact method of the initial intrusion and how the threat actor first gained access to the network remains unclear. However, the leaked data contains a crucial piece of evidence pointing to the core of the attack. According to Ransomnews's analysis, every clone URL used to pull data from all 89 GitLab repositories contained a single, 62-character-long GitLab access token.

This suggests the attacker gained wide-ranging access to the company's most critical software assets using this single credential. This token acted like a "master key," allowing the cloning of the source code for the entire "cs-market" platform, which includes 44 DevOps repositories, 26 backend services, 7 frontends, an API gateway, and all related tooling. If this access token is still active, it poses an ongoing security risk to Żabka. Researchers stated they did not test the token's validity for legal reasons. How this single credential was compromised is now the most critical question of the investigation.

Who Is Affected

If confirmed, this alleged data breach has the potential to directly or indirectly affect multiple groups:

  • Żabka Polska: The company itself stands to suffer the most significant damage from the exposure of its trade secrets, source code, and operational data. This could lead to a loss of competitive advantage, damage to its brand reputation, and increased vulnerability to future cyberattacks.
  • Customers: Although the sample data did not show a high volume of direct customer PII, if the seller's claims about GDPR and bank account data are true, millions of customers could be at risk. The leaked information could be used to launch targeted phishing attacks against customers.
  • Employees: IT service desk tickets and Jira issues may contain employee names, usernames, email addresses, and job descriptions. This information could be exploited for social engineering attacks.
  • Business Partners and Vendors: Technology and consulting firms mentioned in the listing, such as Accenture and Netguru, could also be negatively impacted. The projects and code they developed for Żabka, along with their business relationships, may have been exposed.

What You Can Do

While an official statement from the company is pending, it is important for potentially affected individuals to take proactive measures:

  • For Żabka Customers: Be extra cautious with emails, text messages, and calls that appear to be from Żabka. Do not trust any message that asks for personal information, passwords, or financial details. If you have a Żabka account, it is a good precaution to change your password to a stronger, unique one. Regularly monitor your bank and credit card statements for suspicious activity.
  • For Żabka Employees and Former Employees: Immediately change the passwords for all accounts associated with the company. Enable two-factor authentication (2FA) on your personal and work email accounts. Be prepared for potential phishing attacks targeting you.
  • For General Users: This incident once again highlights the value of digital credentials. Avoid using the same password across different platforms and consider using a reputable password manager to manage your passwords.

What the Company Says

As of the writing of this report on August 3, 2026, Żabka Polska has not issued any official statement regarding the matter. The company has neither confirmed nor denied the data breach allegations. Typically, in such situations, companies conduct an internal investigation to assess the seriousness of the claims and initiate legal notification processes. A statement from the company or the relevant data protection authorities in Poland is expected in the coming days.

Source

https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.