Polish convenience-store chain Żabka has confirmed unauthorised access to selected technical resources through an external service provider.

The disclosure came as an anonymous seller offered allegedly stolen company data for €5,000 on an illicit marketplace. The threat actor claims the files include internal records, source code, production credentials, and Jira data.

Żabka said it detected and blocked the unauthorised access promptly. Based on its initial findings, transaction data and business operations remain secure.

Żabka confirms provider-related incident

A company spokesperson said Żabka learned about suspected unauthorised access at the end of last week.

The access involved selected technical resources in its network and came through an external service provider. Żabka said it responded according to its established security procedures.

The company immediately escalated the matter to its data protection officer. It also notified Poland’s Personal Data Protection Office, known as UODO, in line with legal and internal requirements.

Żabka said it is informing people whose personal information may have been affected. It also pledged to continue monitoring the situation and strengthen its security systems.

The company has not confirmed the full scope of data allegedly taken by the seller.

Threat actor offers alleged data for €5,000

A new account using the name Lumia advertised the alleged dataset on a BreachForums mirror. The seller described the €5,000 asking price as symbolic.

According to the post, the package contains data from approximately 541,000 Jira issues and 2.7 million user references across more than 20 vendor domains.

The seller claims the records include full names, corporate email addresses, Jira usernames, account IDs, and employee or contractor directory information.

The alleged data references external partners including Accenture, Netguru, Onwelo, BlueSoft, and Sygeon.

The post also claims to contain Jira exports from IT service desk operations, including 229,734 tickets. It reportedly includes documentation related to several internal systems, such as the Nowa Kasa point-of-sale system, ZSS sales system, Cyberstore, zMarket, and SAP ERP.

Credentials and source code raise security concerns

The seller further claims to have stolen 89 Git repositories containing nearly 12,000 files. These reportedly cover Żabka’s retail platform, backend microservices, frontend applications, and other infrastructure.

The alleged package also includes production credentials. These include GitLab personal access tokens, database administrator passwords, environment files with hardcoded tokens, and SSH access patterns for store servers.

Cybernews security researcher Rasa Jurgutytė reviewed a 3.1MB archived sample. She said the exposed Jira tickets appeared legitimate based on their format, contents, and Polish-language comments.

The sample reportedly contained 48 JSON files representing internal Jira projects. Another folder held 89 files with GitLab references, including main-branch samples and an OAuth2 key exposed as a URL parameter.

Jurgutytė warned that exposed infrastructure blueprints, credentials, and potential source code could help attackers exploit known flaws and move laterally through connected systems.

The Żabka data breach claims remain partly unverified. However, the company has confirmed an external-provider-related security incident and is working with the relevant authorities.

Żabka operates 13,063 stores across Poland and Romania. The company says it processes 4.3 million transactions each day and recorded 31.1 billion Polish zloty in end-customer sales during 2025.


0 responses to “Żabka Data Breach Claims Put Internal Systems Up for Sale”