
Fakturownia, one of Poland’s major online invoicing platforms, said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The service is used by more than 600,000 businesses, and the company is still working out how many customers are affected. Potentially exposed data includes account and company details, password hashes, bank account information, authentication and integration tokens, and information about customers and business partners. Invoices issued before 2023 may also have been accessed. Payment card data was not affected.
The company says it detected the intrusion on Monday, blocked the attacker, began rotating passwords and application keys, and moved to new servers. Because Fakturownia connects to Poland’s National e-Invoicing System (KSeF), the Finance Ministry reviewed the case and found no breach of KSeF or leak of its data; Fakturownia says its KSeF certificates remain secure. An attacker calling themselves “Fingerprint” told Polish outlet Zaufana Trzecia Strona they stole 6 TB of invoices, a claim that is unverified. The same actor has claimed breaches at Polish healthcare software providers MyDr and Medyc.
How to check if you’re affected
Affected products are Fakturownia accounts and any integrations that use its API or authentication tokens.
- Read the company’s incident notice and follow its instructions for your account.
- Change your Fakturownia password, and anywhere else you reused it. Revoke and reissue API keys and integration tokens, including those used with accounting or e-commerce tools.
- Expect convincing phishing that quotes real invoices or bank details. Verify unexpected payment-change requests by phone before paying.
