Fakturownia breach exposes Polish invoicing platform data
Fakturownia, one of Poland's major online invoicing platforms, has disclosed a data breach that may have exposed information on its users and on their customers and business partners.
The company said an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to its servers. More than 600,000 businesses use the service. Fakturownia has not yet determined how many of them were affected.
What the attacker may have accessed
According to Fakturownia, the potentially compromised data includes:
- user and company account data
- password hashes
- bank account information
- authentication and integration tokens
- information on customers and business partners
The attacker may also have reached invoices issued through the platform before 2023. The company said payment card data and information stored through its integrations were not affected.
Fakturownia detected the intrusion on Monday. It then blocked the attacker, began rotating passwords and application keys, and brought new servers online. It is investigating with outside cybersecurity specialists and has reported the incident to Poland's cybersecurity and data protection authorities.
KSeF not affected, officials say
The incident has drawn extra attention because Fakturownia connects to the National e-Invoicing System (KSeF). KSeF is run by Poland's tax administration, and many businesses are required to use it to issue invoices.
On Wednesday, the Finance Ministry said a review found no breach of KSeF's security and no leak of data held by the system. Fakturownia said separately that the digital certificates used to access KSeF remained secure.
Polish Digital Affairs Minister Krzysztof Gawkowski said on Tuesday that authorities were working to establish the circumstances of the attack.
"This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences," he said.
"Fingerprint" claims 6 TB of invoices
Polish cybersecurity outlet Zaufana Trzecia Strona reported that an attacker calling themselves "Fingerprint" contacted its journalists. The attacker shared material that allegedly shows access to Fakturownia's infrastructure, including screenshots of application directories, customer information and database dumps.
Fingerprint claimed to have stolen 6 terabytes of invoices. That figure has not been independently verified, and neither has the authenticity or full scope of the material.
The same actor has also claimed recent breaches at two Polish healthcare software providers, MyDr and Medyc. In August, Polish cyber officials said the MyDr breach involved unauthorized access to historical data that could relate to roughly 18.8 million people and more than 12,000 medical facilities.
Local authorities are also investigating the intrusion involving Medyc, software used by healthcare providers and developed by Qbusoft.
"The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity," Gawkowski said.
Our Take
The exposed data is the main concern for Fakturownia's customers. Bank account details, business partner information and old invoices are useful material for invoice fraud and convincing phishing. Criminals can use real names, real amounts and real transaction histories to send fake payment requests or "updated" bank details. Businesses that use the platform should treat any unexpected change in a supplier's payment information with suspicion and verify it by phone or another separate channel.
The theft of authentication and integration tokens is also notable. Fakturownia says it is rotating keys, but organisations that connected the platform to other tools should check those connections themselves. They should also change passwords, particularly where the same credentials were reused elsewhere, since password hashes were among the exposed data.
The case follows a familiar pattern of an attacker going to the media with screenshots and large claims before the scope is confirmed, much like the Dodo Pizza breach that followed DataSuckers' claims. Until it is verified, the 6 TB figure should be treated with caution.
More broadly, Fingerprint's apparent run against Polish software vendors suggests a focus on providers that hold data for thousands of downstream businesses or patients. Compromising one supplier can expose many organisations at once. It is worth watching whether Fakturownia publishes a final count of affected customers, whether the stolen data appears for sale or leak, and whether Polish authorities link the three incidents to a single actor or campaign.
