Poland's leading online invoicing service Fakturownia has confirmed suffering a data breach that potentially compromised user information, client details and partner data. An unknown threat actor leveraged a vulnerability to breach the platform's infrastructure, the company announced this week. With more than 600,000 businesses relying on Fakturownia's services, the company is still assessing the full scope of the incident.
The potentially exposed data encompasses account credentials, password hashes, banking details, authentication tokens, integration keys, and records of invoices generated through the platform prior to 2023. Customer and business partner information may also have been accessed. Fakturownia stated that payment card data and information managed through third-party integrations remained uncompromised.
The incident has raised concerns because Fakturownia connects with Poland's National e-Invoicing System (KSeF), administered by the country's tax authority and mandatory for many enterprises. Poland's Finance Ministry announced on Wednesday that an examination determined KSeF itself had not been breached and no data held within the system had been leaked. Fakturownia separately confirmed that the digital certificates required to access KSeF were not compromised.
Fakturownia identified the intrusion on Monday and swiftly responded by cutting off the attacker's access, resetting credentials and application keys, and deploying fresh infrastructure. The company is collaborating with external cybersecurity firms on the investigation and has notified Polish cybersecurity and data protection regulators.
Polish Digital Affairs Minister Krzysztof Gawkowski stated Tuesday that officials were investigating the circumstances surrounding the attack. "This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences," he said.
An individual operating under the alias "Fingerprint" reached out to Polish cybersecurity outlet Zaufana Trzecia Strona and shared materials claiming to demonstrate access to Fakturownia's systems, including directory listings, customer records and database extracts. The attacker asserted having obtained 6 terabytes of invoices, though this claim and the authenticity of the provided materials remain unverified.
Fingerprint has also taken credit for recent intrusions targeting Polish healthcare software vendors MyDr and Medyc. Polish cyber authorities disclosed in August that the MyDr breach involved unauthorized access to historical records potentially affecting approximately 18.8 million individuals and over 12,000 medical institutions. Authorities are separately examining the Medyc incident, which targeted software created by Qbusoft and deployed by healthcare organizations.
"The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity," Gawkowski stated.



