VYPR
breachPublished Oct 1, 2026· 1 source

Polish Invoicing Platform Fakturownia Breached, Exposing Sensitive Business Data

Poland's Fakturownia, a widely used online invoicing platform, has suffered a significant cyberattack, potentially exposing sensitive data of its users, their clients, and business partners.

One of Poland's major online invoicing platforms, Fakturownia, has confirmed a data breach that may have exposed sensitive information belonging to its users, their customers, and business partners. The company, which serves over 600,000 businesses, is currently investigating the full extent of the compromise and how many of its clients were affected.

The attacker reportedly exploited an unspecified vulnerability to gain unauthorized access to Fakturownia's servers. The potentially compromised data includes user and company account details, password hashes, bank account information, authentication and integration tokens, and data pertaining to the platform's customers and business partners. While payment card data and information stored via integrations were reportedly unaffected, the attacker may have also accessed invoices issued through the platform prior to 2023.

The breach has raised particular concern due to Fakturownia's integration with Poland's National e-Invoicing System (KSeF), a mandatory platform operated by the country's tax administration. However, the Finance Ministry has stated that KSeF's security remains intact and no data from the system was leaked. Fakturownia also confirmed that the digital certificates used for KSeF access were not compromised.

Fakturownia detected the unauthorized access on Monday, subsequently blocking the attacker, initiating password and key rotations, and deploying new servers. The company is collaborating with external cybersecurity specialists to investigate the incident and has notified Polish cybersecurity and data protection authorities. Polish Digital Affairs Minister Krzysztof Gawkowski acknowledged the incident, stating that authorities are working to determine the attack's circumstances and that those responsible will face consequences.

Further details emerged as the Polish cybersecurity publication Zaufana Trzecia Strona reported being contacted by an attacker using the alias "Fingerprint." This individual allegedly provided evidence of access to Fakturownia's infrastructure, including screenshots of directories and database dumps, and claimed to have stolen 6 terabytes of invoices. The authenticity and full scope of this claimed data theft have not been independently verified.

Notably, the "Fingerprint" attacker has also claimed responsibility for recent breaches affecting Polish healthcare software providers MyDr and Medyc. The MyDr breach, reported in August, involved historical data potentially affecting approximately 18.8 million individuals and over 12,000 medical facilities. The Medyc intrusion, developed by Qbusoft, is also under separate investigation.

Minister Gawkowski emphasized the need for the private sector to enhance its cybersecurity investments and efforts in light of these repeated attacks. The incident highlights the ongoing challenges businesses face in protecting sensitive data, especially when integrated with critical national infrastructure.

The investigation into the Fakturownia breach is ongoing, with authorities and the company working to fully understand the attack vector, the precise nature of the compromised data, and to implement necessary security enhancements.

Synthesized by Vypr AI