Cyberattack on major Polish invoicing platform exposes customer data

One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.
Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected.
The potentially compromised information includes user and company account data, password hashes, bank account information, authentication and integration tokens, and information belonging to customers and business partners. The attacker may also have accessed invoices issued through Fakturownia before 2023, the company said. Payment card data and information stored through the company’s integrations were not affected.
The breach has drawn scrutiny because Fakturownia integrates with the National e-Invoicing System (KSeF), a platform operated by Poland’s tax administration that many businesses are required to use. The Finance Ministry said Wednesday that a review found no breach of KSeF’s security and no leak of data held by the system. Fakturownia separately said digital certificates used to access KSeF remained secure.
Fakturownia said it detected the unauthorized access on Monday and subsequently blocked the attacker, began rotating passwords and application keys, and brought new servers online. It is investigating the incident with outside cybersecurity specialists and has reported the breach to Poland’s cybersecurity and data protection authorities.
Polish Digital Affairs Minister Krzysztof Gawkowski said Tuesday that authorities were working to establish the circumstances of the attack.
“This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences,” he added.
Polish cybersecurity publication Zaufana Trzecia Strona reported that an attacker using the name “Fingerprint” contacted its journalists and provided material purporting to show access to Fakturownia’s infrastructure, including screenshots of application directories, customer information and database dumps.
The attacker claimed to have stolen 6 terabytes of invoices. That figure, as well as the authenticity and full scope of the purportedly stolen material, has not been independently verified.
Fingerprint has also claimed responsibility for recent breaches involving Polish healthcare software providers MyDr and Medyc.
Polish cyber officials said in August that the MyDr breach involved unauthorized access to historical data that could relate to approximately 18.8 million people and more than 12,000 medical facilities.
Separately, local authorities are investigating the intrusion involving Medyc, software used by healthcare providers that is developed by Qbusoft.
“The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity,” Gawkowski said.
References in this story
- Incydent - oficjalny komunikat - - Fakturownia fakturownia.pl
- Serwis o podatkach - Komunikat Ministerstwa Finansów 30092026 www.podatki.gov.pl portal podatki.gov.pl
- Krzysztof Gawkowski (@KGawkowski) on X x.com Firma Fakturowania, dostarczająca systemy księgowe, padła ofiarą cyberataku. Incydent został zgłoszony do CERT Polska i trwają intensywne prace służb nad ustaleniem dokładnych okoliczności zdarzenia. To kolejny incydent…
- Nowe włamanie "Fingerprinta" - ofiarą firma Fakturownia.pl | Zaufana Trzecia Strona zaufanatrzeciastrona.pl Otrzymaliśmy wiarygodne informacje wskazujące na to, że "Fingerprint", stojący za włamaniami do dwóch serwisów medycznych, tym razem dobrał się do infrastruktury jednej z największych firm oferujących usługi…
- Poland probes MyDr healthcare software breach potentially affecting 19 million people therecord.media MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional…
- Cyberattack on Polish medical software provider exposes patient data therecord.media Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Daryna Antoniuk (@darynant.bsky.social) bsky.app Cybersecurity Reporter at Recorded Future News. Ex at The Kyiv Independent/Forbes/The Kyiv Post 📍Kyiv, Ukraine



