Skip to content
Data breachContained

Fakturownia invoicing platform server breach

Polish online invoicing service Fakturownia, used by more than 600,000 businesses, disclosed that an attacker accessed its servers for about 38 hours and copied account, contractor, invoice and payment data, along with password hashes and API tokens.

Victim
Fakturownia

On 29 September 2026, Fakturownia, one of Poland's most widely used online invoicing platforms with more than 600,000 business customers, disclosed that an attacker had gained unauthorized access to its servers. The company's incident notice says the access lasted from about 03:20 on 27 September until 28 September, when the intrusion was detected, the attacker's IP was blocked and the service was moved to newly built servers.

Fakturownia said the attacker copied extensive customer data, so the breach may concern account data of all users. The exposed material includes account details, password hashes, API tokens, contractor (counterparty) records added before October 2024, payment records and bank account information, and invoice data; full invoice contents dating from before March 2021 were taken, with partial exposure of newer invoices.

Response

The company reported the incident to Poland's data protection authority (UODO), CERT Polska and the Central Bureau for Combating Cybercrime (CBZC). It told customers it would invalidate all API tokens on 1 October 2026 and recommended resetting passwords, regenerating API keys and confirming any request to change bank account details by phone. Poland's Minister of Digital Affairs publicly promised that those responsible would face severe consequences.

Why it matters

Invoicing platforms hold both a company's own data and that of every business it trades with, including bank account numbers. Stolen invoices and counterparty records are ideal material for invoice fraud and business email compromise, in which criminals send convincing requests to change payment details, which is why the company stressed telephone verification of bank account changes.

Timeline

  1. Unauthorized access to Fakturownia's servers begins at about 03:20.

  2. Fakturownia detects the intrusion, blocks the attacker and migrates its service to new servers the same evening.

  3. Fakturownia informs customers and the public, and reports the incident to UODO, CERT Polska and the CBZC.

  4. Fakturownia invalidates all customer API tokens.

Sources

  1. fakturownia.plhttps://fakturownia.pl/incydent
  2. tvpworld.comhttps://tvpworld.com/95653054/popular-polish-invoicing-service-fakturownia-hit-by-cyberattack
  3. portalspozywczy.plhttps://www.portalspozywczy.pl/technologie/wiadomosci/wyciek-danych-z-popularnego-systemu-faktur-korzysta-z-niego-ponad-600-tys-firm,293620.html

Related incidents