Skip to content

Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR

Breach Report Egypt flagEgypt Supply Chain / SaaS Reported Live

Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR

An actor posting as exfilar claims that Qara, an Egyptian supply-chain SaaS platform handling QR anti-counterfeit, feature flags, and mobile app deployment for 14+ enterprise tenants, left its backend databases publicly readable and writable with no authentication. The actor states they modified a production deployment configuration belonging to Saint-Gobain, confirmed it persisted, then reverted it. The dump also covers a Saudi government health and safety application, including 119 government cash voucher records, a national governorate and district dataset, session tokens, and 12 plaintext employee passwords. The actor reports the access remained live as of 5 August. The claim is unverified.

StatusReported live
Tenants14+
Cash vouchers119
Actorexfilar

Post details

TargetQara
CountryEgypt flagEgypt
SectorSupply chain SaaS
ListingReply or upgrade to unlock
Volume32 files / 245MB decompressed
CauseClaimed misconfiguration
Observed
Actorexfilar

!Allegedly included

  • Plaintext employee passwords
  • Database admin keys
  • Search cluster API key
  • 659 session tokens
  • Deployment configurations
  • Feature flag controls
  • Tenant application configs
  • 119 government cash vouchers
  • Voucher IDs & amounts
  • Wallet transaction entries
  • National geographic dataset
  • Phone numbers
  • IP addresses & user agents
  • Supplier data

Screenshots

Potential impact

The stolen data is secondary here. Write access to a database that governs mobile app deployment is a supply-chain compromise, because whoever holds it can alter what software reaches every tenant's workforce. The actor states this was demonstrated against a named multinational and then reverted, meaning the capability was proven rather than theorised. Downstream tenants span construction materials, two major European grocery chains, and a Saudi government body, none of which were themselves breached but all of which inherit the exposure. Separately, government cash vouchers are financial instruments, and plaintext credentials reported as still valid make this an ongoing rather than historical incident.

iStatus

Unverified

The post is unusually detailed, including an infrastructure map, credentials, and an access-status check dated today, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor describes this as the third of roughly 25 planned releases from an automated scanning tool, indicating further targets. Named tenants are customers of the platform, not the breached party. Nothing has been independently corroborated. The claim is unverified and none of the parties has publicly addressed it.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest