A newly registered account on a popular data-leak forum has reportedly placed an alleged dataset belonging to Żabka Polska up for sale with a price tag of €5,000. The leak purportedly includes hundreds of thousands of internal Jira issues and service-desk tickets, alongside source code extracted from nearly 90 GitLab repositories. According to Security Affairs, researchers have analyzed sample archives provided by the seller and noted a high level of internal consistency regarding the volumes of claimed data, though the firm has yet to officially acknowledge or confirm the incident.
The compromised material reportedly mentions several critical systems, including the company's 'Nowa Kasa' point-of-sale platform, SAP ERP tools, and integrations with external vendors such as Accenture and Netguru. While the seller's documentation for total Jira and IT ticket counts matches the sample files provided, secondary claims regarding specific volumes of GDPR-related records and customer bank accounts were not substantiated by the available samples. Cybersecurity experts suggest that these discrepancies might arise from how the data was initially sampled, or they could indicate marketing embellishment by the actor behind the sale.
Of particular concern to security professionals is the inclusion of a valid, 62-character GitLab access token embedded within the repository dumps. The presence of such credentials poses a substantial risk to the integrity of the affected systems, as it could allow unauthorized parties to gain persistent access to the company's development environment. As of this report, Żabka Group has not provided a formal statement confirming the breach, leaving the full extent of the potential exposure uncertain. Security teams continue to monitor the situation for further developments and to assess the impact on the firm’s operational infrastructure and third-party vendor network.
Reader Discussion & Insights