Cyberattack on major Polish invoicing platform exposes customer data
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.
Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected.
The potentially compromised information includes user and company account data, password hashes, bank account information, authentication and integration tokens, and information belonging to customers and business partners. The attacker may also have accessed invoices issued through Fakturownia before 2023, the company said. Payment card data and information stored through the company’s integrations were not affected.
The breach has drawn scrutiny because Fakturownia integrates with the National e-Invoicing System (KSeF), a platform operated by Poland’s tax administration that many businesses are required to use. The Finance Ministry said Wednesday that a review found no breach of KSeF’s security and no leak of data held by the system. Fakturownia separately said digital certificates used to access KSeF remained secure.
Fakturownia said it detected the unauthorized access on Monday and subsequently blocked the attacker, began rotating passwords and application keys, and brought new servers online. It is investigating the incident with outside cybersecurity specialists and has reported the breach to Poland’s cybersecurity and data protection authorities.
Polish Digital Affairs Minister Krzysztof Gawkowski said Tuesday that authorities were working to establish the circumstances of the attack.
“This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences,” he added.
Polish cybersecurity publication Zaufana Trzecia Strona reported that an attacker using the name “Fingerprint” contacted its journalists and provided material purporting to show access to Fakturownia’s infrastructure, including screenshots of application directories, customer information and database dumps.
The attacker claimed to have stolen 6 terabytes of invoices. That figure, as well as the authenticity and full scope of the purportedly stolen material, has not been independently verified.
Fingerprint has also claimed responsibility for recent breaches involving Polish healthcare software providers MyDr and Medyc.
Polish cyber officials said in August that the MyDr breach involved unauthorized access to historical data that could relate to approximately 18.8 million people and more than 12,000 medical facilities.
Separately, local authorities are investigating the intrusion involving Medyc, software used by healthcare providers that is developed by Qbusoft.
“The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity,” Gawkowski said.
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.



