Żabka Polska, BlueSoft, Accenture and Netguru: Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

Żabka Polska, BlueSoft, Accenture and Netguru: Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

Alleged Żabka Breach Exposes Sensitive Data, Including Jira Records and Source Code

On August 2, 2026, an unknown threat actor listed an alleged data breach of Żabka Polska, Poland’s largest convenience store chain, for sale on a cybercrime forum. The seller, operating under a newly created account, demanded €5,000 for a dataset reportedly containing 541,000 Jira issues, 229,734 IT service-desk tickets, and source code from 89 GitLab repositories. The leak also referenced internal systems, including Żabka’s point-of-sale platform (Nowa Kasa), Cyberstore, zMarket, SAP ERP, and integrations with third-party vendors like Accenture, Netguru, and BlueSoft.

Researchers at Ransomnews analyzed a sample of the data and confirmed that the claimed figures largely matched the provided evidence. However, two high-profile numbers 35,206 GDPR (RODO) references and 4,000 bank account mentions were notably absent from the sample, raising questions about their accuracy. The most concerning discovery was a single GitLab access token embedded in all 89 repository dumps, suggesting a potential compromise of Żabka’s entire cs-market platform, including 44 DevOps repositories, 26 backend services, seven frontends, and an API gateway. The repositories also contained live secrets, such as Cloudflare API keys, MongoDB admin passwords, and messaging broker credentials.

Żabka has not confirmed the breach, and the company has remained silent on whether it has notified Polish authorities under GDPR’s 72-hour reporting requirement. The timing of the leak is particularly notable, as it surfaced just two days after Alimentation Couche-Tard announced a €7.56 billion acquisition offer for Żabka on July 31. While there is no evidence linking the two events, the leak’s emergence during due diligence could raise legal and security concerns for the buyer.

The incident aligns with a growing trend of infostealer malware compromising employee credentials, allowing attackers to exfiltrate data through legitimate access points. The seller’s lack of prior forum activity further complicates verification, leaving the authenticity of the full dataset uncertain. If the GitLab token remains active, the potential for ongoing unauthorized access to Żabka’s codebase and infrastructure could pose significant risks.

Source: https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-data-source-code-and-api-keys.html

Żabka Polska TPRM report: https://www.rankiteo.com/company/zabka-group

BlueSoft TPRM report: https://www.rankiteo.com/company/bluesoft

Accenture TPRM report: https://www.rankiteo.com/company/accenturepoland

Netguru TPRM report: https://www.rankiteo.com/company/netguru

"id": "acczabnetblu1785752860",
"linkid": "accenturepoland, zabka-group, netguru, bluesoft",
"type": "Breach",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Retail',
                        'location': 'Poland',
                        'name': 'Żabka Polska',
                        'size': "Large (Poland's largest convenience store "
                                'chain)',
                        'type': 'Convenience Store Chain'}],
 'attack_vector': 'Infostealer Malware',
 'data_breach': {'data_exfiltration': 'Yes (data listed for sale on cybercrime '
                                      'forum)',
                 'file_types_exposed': ['Jira records',
                                        'IT service-desk tickets',
                                        'GitLab repository dumps'],
                 'number_of_records_exposed': '541,000 Jira issues, 229,734 IT '
                                              'service-desk tickets',
                 'personally_identifiable_information': 'Potential (GDPR '
                                                        'references, bank '
                                                        'account mentions)',
                 'sensitivity_of_data': 'High (source code, live secrets, '
                                        'potential PII/GDPR data)',
                 'type_of_data_compromised': ['Jira issues',
                                              'IT service-desk tickets',
                                              'Source code',
                                              'GitLab access tokens',
                                              'Live secrets (API keys, '
                                              'passwords, credentials)',
                                              'Potential GDPR references',
                                              'Potential bank account '
                                              'mentions']},
 'date_detected': '2026-08-02',
 'date_publicly_disclosed': '2026-08-02',
 'description': 'An unknown threat actor listed an alleged data breach of '
                'Żabka Polska, Poland’s largest convenience store chain, for '
                'sale on a cybercrime forum. The dataset reportedly contains '
                '541,000 Jira issues, 229,734 IT service-desk tickets, and '
                'source code from 89 GitLab repositories. The leak also '
                'referenced internal systems, including Żabka’s point-of-sale '
                'platform (Nowa Kasa), Cyberstore, zMarket, SAP ERP, and '
                'integrations with third-party vendors like Accenture, '
                'Netguru, and BlueSoft. The breach included a GitLab access '
                'token embedded in all 89 repository dumps, suggesting a '
                'potential compromise of Żabka’s entire cs-market platform, '
                'along with live secrets such as Cloudflare API keys, MongoDB '
                'admin passwords, and messaging broker credentials.',
 'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
                                       'unconfirmed breach during acquisition '
                                       'due diligence',
            'data_compromised': '541,000 Jira issues, 229,734 IT service-desk '
                                'tickets, source code from 89 GitLab '
                                'repositories, live secrets (Cloudflare API '
                                'keys, MongoDB admin passwords, messaging '
                                'broker credentials), potential GDPR '
                                'references and bank account mentions',
            'legal_liabilities': 'Potential GDPR violations if breach is '
                                 'confirmed',
            'operational_impact': 'Potential unauthorized access to codebase '
                                  'and infrastructure, risk of further '
                                  'exploitation',
            'systems_affected': ['Nowa Kasa (POS platform)',
                                 'Cyberstore',
                                 'zMarket',
                                 'SAP ERP',
                                 'GitLab repositories (cs-market platform)',
                                 'Third-party vendor integrations (Accenture, '
                                 'Netguru, BlueSoft)']},
 'initial_access_broker': {'data_sold_on_dark_web': 'Yes (listed for sale on '
                                                    'cybercrime forum)',
                           'entry_point': 'Compromised employee credentials '
                                          '(infostealer malware)',
                           'high_value_targets': 'GitLab repositories, '
                                                 'internal systems (Nowa Kasa, '
                                                 'SAP ERP, etc.)'},
 'investigation_status': 'Unconfirmed (Żabka has not verified the breach)',
 'motivation': 'Financial Gain',
 'post_incident_analysis': {'root_causes': 'Infostealer malware leading to '
                                           'compromised employee credentials, '
                                           'potential lack of multi-factor '
                                           'authentication or secret '
                                           'management'},
 'ransomware': {'data_exfiltration': 'Yes', 'ransom_demanded': '€5,000'},
 'references': [{'date_accessed': '2026-08-02', 'source': 'Ransomnews'}],
 'regulatory_compliance': {'regulations_violated': ['Potential GDPR (RODO) '
                                                    'violations']},
 'response': {'communication_strategy': 'No public confirmation or statement '
                                        'from Żabka'},
 'threat_actor': 'Unknown',
 'title': 'Alleged Żabka Breach Exposes Sensitive Data, Including Jira Records '
          'and Source Code',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Compromised Employee Credentials'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.