> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
- URL: https://darkwebinformer.com/qara-platform-allegedly-exposed-actor-claims-live-write-access-to-app-deployment-for-saint-gobain-lidl-and-spar/
- Published: 2026-08-05T16:43:44.000Z
- Updated: 2026-08-05T16:44:27.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Breach Report ![Egypt flag](https://flagcdn.com/w40/eg.png)Egypt Supply Chain / SaaS Reported Live 

## Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR

An actor posting as **exfilar** claims that **Qara**, an Egyptian supply-chain SaaS platform handling QR anti-counterfeit, feature flags, and mobile app deployment for **14+ enterprise tenants**, left its backend databases publicly readable **and writable** with no authentication. The actor states they **modified a production deployment configuration belonging to Saint-Gobain, confirmed it persisted, then reverted it**. The dump also covers a Saudi government health and safety application, including **119 government cash voucher records**, a national governorate and district dataset, session tokens, and **12 plaintext employee passwords**. The actor reports the access **remained live as of 5 August**. The claim is **unverified**.

Severity CRITICAL 

StatusReported live

Tenants14+

Cash vouchers119

Actorexfilar

### ▣Post details

TargetQara

Country![Egypt flag](https://flagcdn.com/w40/eg.png)Egypt

SectorSupply chain SaaS

ListingReply or upgrade to unlock

Volume32 files / 245MB decompressed

CauseClaimed misconfiguration

ObservedAug 5, 2026

Actorexfilar

### !Allegedly included

- Plaintext employee passwords
- Database admin keys
- Search cluster API key
- 659 session tokens
- Deployment configurations
- Feature flag controls
- Tenant application configs
- 119 government cash vouchers
- Voucher IDs & amounts
- Wallet transaction entries
- National geographic dataset
- Phone numbers
- IP addresses & user agents
- Supplier data

### ◱Screenshots

[ ![Qara supply chain SaaS platform data exposure forum post screenshot, August 2026 (1 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235871.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235871.png) [ ![Qara supply chain SaaS platform data exposure forum post screenshot, August 2026 (2 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235872.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235872.png) [ ![Qara supply chain SaaS platform data exposure forum post screenshot, August 2026 (3 of 3)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235873.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/87632148957618972458729653897235873.png) 

### ⚠Potential impact

The stolen data is secondary here. **Write access to a database that governs mobile app deployment is a supply-chain compromise**, because whoever holds it can alter what software reaches every tenant's workforce. The actor states this was demonstrated against a named multinational and then reverted, meaning the capability was **proven rather than theorised**. Downstream tenants span construction materials, two major European grocery chains, and a Saudi government body, none of which were themselves breached but all of which inherit the exposure. Separately, **government cash vouchers are financial instruments**, and plaintext credentials reported as still valid make this an **ongoing rather than historical** incident.

### iStatus

Unverified 

The post is unusually detailed, including an infrastructure map, credentials, and an access-status check dated today, **none of which Dark Web Informer is reproducing while the exposure is reported as unremediated**. The actor describes this as the third of roughly 25 planned releases from an automated scanning tool, indicating further targets. Named tenants are **customers of the platform, not the breached party**. Nothing has been independently corroborated. The claim is **unverified** and none of the parties has publicly addressed it.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE