Egypt
Supply Chain / SaaS
Reported Live
Qara Platform Allegedly Exposed, Actor Claims Live Write Access to App Deployment for Saint-Gobain, Lidl and SPAR
An actor posting as exfilar claims that Qara, an Egyptian supply-chain SaaS platform handling QR anti-counterfeit, feature flags, and mobile app deployment for 14+ enterprise tenants, left its backend databases publicly readable and writable with no authentication. The actor states they modified a production deployment configuration belonging to Saint-Gobain, confirmed it persisted, then reverted it. The dump also covers a Saudi government health and safety application, including 119 government cash voucher records, a national governorate and district dataset, session tokens, and 12 plaintext employee passwords. The actor reports the access remained live as of 5 August. The claim is unverified.
▣Post details
Egypt!Allegedly included
- Plaintext employee passwords
- Database admin keys
- Search cluster API key
- 659 session tokens
- Deployment configurations
- Feature flag controls
- Tenant application configs
- 119 government cash vouchers
- Voucher IDs & amounts
- Wallet transaction entries
- National geographic dataset
- Phone numbers
- IP addresses & user agents
- Supplier data
◱Screenshots
⚠Potential impact
The stolen data is secondary here. Write access to a database that governs mobile app deployment is a supply-chain compromise, because whoever holds it can alter what software reaches every tenant's workforce. The actor states this was demonstrated against a named multinational and then reverted, meaning the capability was proven rather than theorised. Downstream tenants span construction materials, two major European grocery chains, and a Saudi government body, none of which were themselves breached but all of which inherit the exposure. Separately, government cash vouchers are financial instruments, and plaintext credentials reported as still valid make this an ongoing rather than historical incident.
iStatus
UnverifiedThe post is unusually detailed, including an infrastructure map, credentials, and an access-status check dated today, none of which Dark Web Informer is reproducing while the exposure is reported as unremediated. The actor describes this as the third of roughly 25 planned releases from an automated scanning tool, indicating further targets. Named tenants are customers of the platform, not the breached party. Nothing has been independently corroborated. The claim is unverified and none of the parties has publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE