Fakturownia breach exposes data on Polish invoicing platform
Polish invoicing provider Fakturownia says an attacker exploited a flaw to reach servers holding account data, password hashes, bank details and tokens; 'Fingerprint' claims 6 TB.
Fakturownia, a Polish online invoicing platform used by more than 600,000 businesses, has disclosed a breach after an attacker exploited a vulnerability in its systems and reached its servers. A threat actor using the handle "Fingerprint" claims to have taken 6 TB of invoices — a figure that is not independently verified.
What's exposed
Per reporting at The Record, Fakturownia's incident statement describes exposure of:
- user and company account data
- password hashes
- bank account information
- authentication and integration tokens
- customer and business-partner information
- invoices issued before 2023
Tokens and bank details are the sharp end here: integration tokens can grant onward access to connected systems, and the pre-2023 invoice trove is a ready-made dataset for business-email-compromise and invoice-fraud pretexting.
Timeline and attribution
- 30 September 2026 — breach detected.
- 1 October 2026 — public disclosure.
Fakturownia says an unidentified attacker exploited a vulnerability to gain unauthorized server access; the specific flaw has not been published. "Fingerprint" also claims responsibility for the MyDr (18M+ people) and Medyc (5M) breaches, per The Record — a claim worth noting but not yet corroborated against those victims' own statements.
Poland's Finance Ministry confirmed that the National e-Invoicing System (KSeF) remained secure and was not affected.
What to do today
- If you integrate with Fakturownia, rotate every API and integration token now — tokens are in scope, and rotation is the one action that doesn't wait on the vendor's forensics.
- Force password resets for accounts tied to the platform; hashed does not mean safe once the hashes are offline.
- Treat historical invoice data as compromised and brief finance teams on invoice-fraud and payment-redirect lures referencing real past transactions.
- Watch bank-detail exposure: monitor the accounts named in your Fakturownia records for fraudulent activity.
Context
This lands on the same day France confirmed a data leak at e-invoicing provider VosFactures — whose technical backend is, per French reporting, also Fakturownia (covered in our French edition). Whether the two incidents share a root cause or a single intrusion is not yet established, but invoicing platforms are becoming a recurring soft target: they concentrate financial relationships, tax identifiers, and payment details across thousands of businesses, and a single provider breach ripples out to every customer's books.