logo

Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

ID: 31aeb45e-e8b7-5fcc-ab51-32cbfd18ed93

STIX ID: report--31aeb45e-e8b7-5fcc-ab51-32cbfd18ed93

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Pierluigi Paganini

...
...

Alleged Żabka Polska breach: a forum listing offered a dataset (541k Jira issues, ~230k IT tickets, 89 GitLab repo dumps) and attached a sample that largely matches the seller's counts; the sample contains a single 62-character GitLab access token reused across repo exports and multiple live-looking secrets (Cloudflare API keys, MongoDB admin password, messaging broker credentials), suggesting potential complete codebase and credential exposure though full breach confirmation and active exploitation remain unproven.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.