Alleged Żabka data leak raises alarms over exposed Jira, GitLab secrets

A brand-new forum account popped up on August 2 with a single listing: 5,000 euros for what it claimed was a full data dump on Żabka Polska, Poland’s largest convenience-store chain. Independent researchers who sampled the archive found enough internal consistency to take the claim seriously—including 541,000 Jira issues, 230,000 IT service-desk tickets, and source code from 89 GitLab repositories. Żabka has not confirmed a breach.
What the leak purports to contain
The seller’s headline numbers line up closely when checked against the sample files. Forty-eight Jira exports tally to 541,463 issues—matching the headline almost exactly—and the IT service-desk export hits its stated total on the nose. Names of real internal systems appear in the dumps, including the point-of-sale platform Nowa Kasa, Cyberstore, zMarket, and SAP ERP, alongside integrations with Accenture, Netguru, and BlueSoft. Yet two flashy counts—35,206 GDPR references and roughly 4,000 bank-account mentions—did not appear in the sample, casting doubt on the seller’s precision.
The real risk: one credential, one platform
The most consequential artifact in the sample is a single 62-character GitLab access token, embedded in the clone URL of every one of the 89 repository dumps. According to the review, that token could have been used to clone Żabka’s entire cs-market platform: 44 devops repositories, 26 backend services, seven frontends, the API gateway and tooling. The researchers did not test the token for validity or continued access, citing legal and ethical concerns.
No confirmation, but lessons already clear
Żabka has not responded publicly to the allegations. Independent verification shows parts of the claim are plausible, yet the seller’s secondary statistics look more like marketing than evidence. The presence of a single, reusable credential across so many repositories underscores a systemic issue: overly permissive access can turn a single leak into a full codebase compromise.
Why it matters
Even if Żabka’s systems were not ultimately accessed by an attacker, the incident spotlights how a single leaked credential can expose core infrastructure. For retailers running franchise networks, the stakes include operational continuity, customer trust, and regulatory exposure. Companies should audit repository access tokens, enforce least-privilege principles, and validate breach claims through independent sampling before paying ransoms or engaging with dark-web listings.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

