Attacker Gained Server Access, Company Says Payment Card Data Was Not Compromised
Fakturownia, a major Polish online invoicing platform used by more than 600,000 businesses, has confirmed a data breach after an attacker exploited a vulnerability in its systems to gain unauthorized server access. The company detected the intrusion on Monday, September 30, 2026, and disclosed the incident publicly later that week.
Exposed data includes user and company account information, password hashes, bank account details, and authentication and integration tokens, along with customer and business-partner information and invoices issued before 2023. Fakturownia says payment card data and information stored within third-party integrations were not compromised, and that digital certificates tied to its KSeF (Poland's national e-invoicing system) integration remain secure.
Incident Details
| Attribute | Value |
|---|---|
| Victim | Fakturownia (Polish online invoicing platform) |
| User base | 600,000+ businesses |
| Detection date | September 30, 2026 |
| Attack vector | Exploitation of a vulnerability granting unauthorized server access |
| Data exposed | Account data, password hashes, bank account details, auth/integration tokens, customer and partner info, pre-2023 invoices |
| Data NOT exposed | Payment card data; third-party integration-stored data; KSeF digital certificates |
| Affected user count | Not yet finalized — company still investigating scope |
| Attacker claim | Alleged theft of 6 terabytes of invoices (unverified) |
| Threat actor alias | "Fingerprint" |
Company Response
Fakturownia says it has:
- Blocked the attacker's access to its systems
- Rotated passwords and application keys across affected infrastructure
- Deployed new servers to replace potentially compromised infrastructure
- Engaged outside cybersecurity specialists to investigate the incident
- Reported the breach to Polish cybersecurity and data protection authorities
- Confirmed that digital certificates used for its KSeF national e-invoicing integration remain secure and were not part of the exposure
The company says it is still determining the exact number of customers affected and has not independently verified the attacker's claim of stolen data volume.
Attribution
An individual using the alias "Fingerprint" contacted journalists claiming responsibility for the breach and asserting that 6 terabytes of invoices were stolen — a figure Fakturownia has not confirmed. The same alias has also claimed responsibility for recent breaches of two other Polish software providers in the healthcare sector: MyDr and Medyc. Those claims, taken together, suggest a threat actor running a pattern of intrusions against Polish SaaS platforms rather than a one-off incident against Fakturownia specifically — though CosmicBytez Labs has not independently verified the connection between the three claimed breaches.
Impact Assessment
| Impact Area | Description |
|---|---|
| Credential exposure | Stolen password hashes create offline cracking risk; affected users should treat their Fakturownia password as compromised regardless of hash strength |
| Financial data exposure | Bank account details tied to invoicing records raise risk of targeted phishing or fraud against exposed businesses and their customers |
| Token/API exposure | Stolen authentication and integration tokens could allow an attacker to access connected services if not promptly rotated by affected customers |
| Business/customer data | Exposure of invoices and business-partner data extends breach impact beyond Fakturownia's direct users to their downstream customers and vendors |
| Sector pattern | A threat actor publicly claiming multiple Polish SaaS breaches (invoicing, healthcare software) suggests a broader targeting campaign against Polish business software providers |
Recommendations
For Fakturownia customers
- Change your Fakturownia account password immediately, and avoid reusing it on any other service.
- Rotate any API keys or integration tokens connected to your Fakturownia account (accounting software, payment processors, e-commerce platforms).
- Monitor business bank accounts referenced in Fakturownia invoices for unusual activity or targeted phishing referencing real invoice details.
- Notify your own customers or partners if their data appeared in invoices you issued through the platform before 2023, as you may have independent disclosure obligations.
For security teams at SaaS providers
- Treat server-level access vulnerabilities in invoicing/financial software as high priority given the sensitivity of bank and identity data such platforms accumulate by design.
- Maintain segregation between application servers and stored financial/credential data so a single server compromise doesn't yield bank details and password hashes together.
- Prepare incident communications in advance for breaches involving unverified attacker claims about data volume, to avoid under- or over-stating exposure before investigation concludes.
Key Takeaways
- Fakturownia, a Polish invoicing platform serving 600,000+ businesses, confirmed a breach after an attacker gained unauthorized server access via an exploited vulnerability.
- Exposed data includes password hashes, bank account details, authentication tokens, and invoices issued before 2023 — payment card data was not affected.
- The company has blocked the attacker, rotated credentials, deployed new servers, and reported the incident to Polish authorities.
- An attacker using the alias "Fingerprint" claims 6 terabytes of stolen invoices — unverified — and claims responsibility for separate breaches at Polish healthcare software firms MyDr and Medyc.
- The exact number of affected users has not yet been determined; Fakturownia's investigation is ongoing.
- Affected businesses should rotate passwords and API tokens immediately and monitor for fraud tied to exposed bank account information.