Cyberattack on Polish invoicing platform Fakturownia exposes data of all accounts

Fakturownia, a Polish e-invoicing service with more than 600,000 customers, says an attacker exploited a vulnerability and copied account data, password hashes, API tokens and bank details.

Cyberattack on Polish invoicing platform Fakturownia exposes data of all accounts

At a glance

  • Unauthorized access lasted from September 27 to September 28, according to the company's incident notice
  • Exposed data includes account and company details, password hashes, API and integration tokens and bank account information
  • Poland's Finance Ministry says the national KSeF e-invoicing system was not breached; payment card data was not affected
  • A hacker using the alias Fingerprint claimed the attack and said 6 TB of invoices were stolen, which is unverified

Fakturownia, a major Polish online invoicing platform that says it serves more than 600,000 customers in Poland and abroad, has disclosed a cyberattack in which an intruder copied a large part of its database, including account data, password hashes, API tokens and bank account details. The Record reported on October 1, 2026 that the company detected the unauthorized access on Monday and blocked the attacker. In an incident notice, Fakturownia said the breach affects every account on the platform.

What happened

According to the company's official notice, an unauthorized person exploited a vulnerability in its systems and had access from around 3:20 a.m. on September 27 until around 5:45 p.m. on September 28, 2026. Fakturownia said it first blocked the attacker's address on September 28, removed the attacker's access the same day, rotated application keys and service passwords and moved traffic to newly built servers. It notified CERT Polska, the data protection authority UODO and police on September 29 and began sending individual notifications to users on October 1.

A hacker using the alias "Fingerprint" claimed responsibility, The Record reported, providing material purporting to show access to Fakturownia's infrastructure and claiming to have stolen 6 terabytes of invoices. The Record noted that these claims have not been independently verified. The same alias has previously claimed breaches of Polish healthcare platforms MyDr and Medyc.

Technical details

Fakturownia's notice lists company and user data such as names, tax identification numbers, addresses, email addresses and phone numbers, as well as password hashes, session identifiers, API tokens and integration keys, bank account numbers and payment information. The company said contractor data added before October 16, 2024 and full invoice content issued before March 22, 2021 were also copied, while Sekurak reported that invoice amounts and payment status were exposed for the entire history. The Record's initial report said invoices issued before 2023 may have been accessed; the company's more detailed notice gives the dates above.

Fakturownia said KSeF certificates, bank login credentials and payment card data were not affected, noting it does not store them. Poland's Finance Ministry said a review found no breach of the National e-Invoicing System (KSeF) and no leak of data held by it, according to The Record.

Who is affected

The incident concerns all Fakturownia users and the business partners whose details appear in their accounts. Digital Affairs Minister Krzysztof Gawkowski said those responsible "are being pursued" and urged the private sector to invest more in cybersecurity, The Record reported.

What to do

Fakturownia advised users to change their passwords, regenerate API keys used in third-party integrations and change passwords on other services where the same credentials were reused. The company also urged customers to check account settings, especially bank account details, to confirm any unusual payment request by phone using a previously known number, and to ignore messages asking for passwords, verification codes or card details. The company said existing API keys now only work from previously used IP addresses. Because bank details and invoice data were exposed, businesses should be alert to invoice fraud and fake requests to change payment accounts.

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.