NEWS

Fakturownia Breach Exposes Password Hashes, Bank Data of Polish Invoicing Platform

Fakturownia, used by 600,000+ Polish businesses, confirms a breach exposing password hashes, bank details, and API tokens after server access.

Dylan H.

News Desk

October 2, 2026
5 min read
Fakturownia Breach Exposes Password Hashes, Bank Data of Polish Invoicing Platform

Attacker Gained Server Access, Company Says Payment Card Data Was Not Compromised

Fakturownia, a major Polish online invoicing platform used by more than 600,000 businesses, has confirmed a data breach after an attacker exploited a vulnerability in its systems to gain unauthorized server access. The company detected the intrusion on Monday, September 30, 2026, and disclosed the incident publicly later that week.

Exposed data includes user and company account information, password hashes, bank account details, and authentication and integration tokens, along with customer and business-partner information and invoices issued before 2023. Fakturownia says payment card data and information stored within third-party integrations were not compromised, and that digital certificates tied to its KSeF (Poland's national e-invoicing system) integration remain secure.


Incident Details

AttributeValue
VictimFakturownia (Polish online invoicing platform)
User base600,000+ businesses
Detection dateSeptember 30, 2026
Attack vectorExploitation of a vulnerability granting unauthorized server access
Data exposedAccount data, password hashes, bank account details, auth/integration tokens, customer and partner info, pre-2023 invoices
Data NOT exposedPayment card data; third-party integration-stored data; KSeF digital certificates
Affected user countNot yet finalized — company still investigating scope
Attacker claimAlleged theft of 6 terabytes of invoices (unverified)
Threat actor alias"Fingerprint"

Company Response

Fakturownia says it has:

  • Blocked the attacker's access to its systems
  • Rotated passwords and application keys across affected infrastructure
  • Deployed new servers to replace potentially compromised infrastructure
  • Engaged outside cybersecurity specialists to investigate the incident
  • Reported the breach to Polish cybersecurity and data protection authorities
  • Confirmed that digital certificates used for its KSeF national e-invoicing integration remain secure and were not part of the exposure

The company says it is still determining the exact number of customers affected and has not independently verified the attacker's claim of stolen data volume.


Attribution

An individual using the alias "Fingerprint" contacted journalists claiming responsibility for the breach and asserting that 6 terabytes of invoices were stolen — a figure Fakturownia has not confirmed. The same alias has also claimed responsibility for recent breaches of two other Polish software providers in the healthcare sector: MyDr and Medyc. Those claims, taken together, suggest a threat actor running a pattern of intrusions against Polish SaaS platforms rather than a one-off incident against Fakturownia specifically — though CosmicBytez Labs has not independently verified the connection between the three claimed breaches.


Impact Assessment

Impact AreaDescription
Credential exposureStolen password hashes create offline cracking risk; affected users should treat their Fakturownia password as compromised regardless of hash strength
Financial data exposureBank account details tied to invoicing records raise risk of targeted phishing or fraud against exposed businesses and their customers
Token/API exposureStolen authentication and integration tokens could allow an attacker to access connected services if not promptly rotated by affected customers
Business/customer dataExposure of invoices and business-partner data extends breach impact beyond Fakturownia's direct users to their downstream customers and vendors
Sector patternA threat actor publicly claiming multiple Polish SaaS breaches (invoicing, healthcare software) suggests a broader targeting campaign against Polish business software providers

Recommendations

For Fakturownia customers

  • Change your Fakturownia account password immediately, and avoid reusing it on any other service.
  • Rotate any API keys or integration tokens connected to your Fakturownia account (accounting software, payment processors, e-commerce platforms).
  • Monitor business bank accounts referenced in Fakturownia invoices for unusual activity or targeted phishing referencing real invoice details.
  • Notify your own customers or partners if their data appeared in invoices you issued through the platform before 2023, as you may have independent disclosure obligations.

For security teams at SaaS providers

  • Treat server-level access vulnerabilities in invoicing/financial software as high priority given the sensitivity of bank and identity data such platforms accumulate by design.
  • Maintain segregation between application servers and stored financial/credential data so a single server compromise doesn't yield bank details and password hashes together.
  • Prepare incident communications in advance for breaches involving unverified attacker claims about data volume, to avoid under- or over-stating exposure before investigation concludes.

Key Takeaways

  1. Fakturownia, a Polish invoicing platform serving 600,000+ businesses, confirmed a breach after an attacker gained unauthorized server access via an exploited vulnerability.
  2. Exposed data includes password hashes, bank account details, authentication tokens, and invoices issued before 2023 — payment card data was not affected.
  3. The company has blocked the attacker, rotated credentials, deployed new servers, and reported the incident to Polish authorities.
  4. An attacker using the alias "Fingerprint" claims 6 terabytes of stolen invoices — unverified — and claims responsibility for separate breaches at Polish healthcare software firms MyDr and Medyc.
  5. The exact number of affected users has not yet been determined; Fakturownia's investigation is ongoing.
  6. Affected businesses should rotate passwords and API tokens immediately and monitor for fraud tied to exposed bank account information.

Sources