Fakturownia, one of Poland's major online invoicing platforms used by more than 600,000 businesses, said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorised access to servers; it detected the intrusion on Monday (28 September), blocked the attacker and reported the breach to Poland's cybersecurity and data protection authorities. Potentially compromised data includes user and company account data, password hashes, bank account information, authentication and integration tokens, and information belonging to customers and business partners; invoices issued before 2023 may also have been reached. Payment card data was not affected. The breach draws scrutiny because Fakturownia integrates with the National e-Invoicing System (KSeF), operated by Poland's tax administration; the Finance Ministry said on 30 September that its review found no breach of KSeF and no leak of data held there, and Fakturownia said KSeF access certificates remained secure. An attacker calling themselves "Fingerprint" — who also claimed the MyDr and Medyc healthcare software breaches — claims to have stolen 6 terabytes of invoices; that figure and the material's authenticity are unverified victim-adversary claims, and Fakturownia is still determining how many customers were affected.
| Attribute | Detail |
|---|---|
| Sector | Financial Services |
| Date | 2026-10-02 |
| Source | The Record |
| Reliability | Tier 2 |