Security1 publisher3 min readPublished
Fakturownia breach may have exposed bank details and integration tokens of its invoicing customers
Polish invoicing platform Fakturownia, used by over 600,000 businesses, says an attacker may have reached bank details, password hashes and integration tokens. With the count of affected accounts still open, the listed data already supports forged bank-change notices to customers' business partners.
The Watch · Security desk

What happened
- Fakturownia detected the intrusion on Monday, blocked the attacker, began rotating passwords and application keys, and brought new servers online.
- Poland's Finance Ministry said on Wednesday that its review found no breach of the state KSeF e-invoicing system and no leak of the data it holds.
- An attacker calling itself Fingerprint, who claims the Fakturownia intrusion, has also claimed recent breaches at Polish healthcare software providers MyDr and Medyc.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Business partners of Fakturownia users become targets for payment-redirection fraud, since the attacker may hold both their supplier relationships and the bank accounts they expect to pay.
- decision Customers running integrations must choose between waiting for Fakturownia to confirm its rotation covered their tokens and revoking and reissuing those tokens themselves.
- constraint If the ministry and the company are right about KSeF, the attacker's reach ends at Fakturownia's own records and does not extend into the mandatory state invoicing system.
- precedent If Fingerprint's claims hold, its targets are Polish software vendors holding records for many client organisations, so each further breach would expose downstream businesses in bulk.
I'd rate one pairing on Fakturownia's list as the most exploitable: bank account information held alongside data belonging to its users' customers and business partners [3]. An invoicing platform holds the record of who bills whom. The company says the attacker may also have reached invoices issued before 2023 [4]. With those, a forged notice telling a buyer that a supplier's bank account has changed can cite invoices the buyer actually paid. Sending one needs no further access to Fakturownia.
An unidentified attacker got in by exploiting a vulnerability in Fakturownia's systems to reach its servers [1]. Authentication and integration tokens are among the potentially compromised data [3]. The company says information stored through its integrations was not affected [5], but it lists the tokens that connect those integrations separately as potentially compromised [3]. The company did not say whether the key rotation it began on Monday [9] revoked every integration token its customers issued, or which algorithm produced the password hashes.
The part that drew government attention looks contained. Fakturownia connects to KSeF, the tax administration's e-invoicing system that many businesses are required to use [6]. Beyond the ministry's review, Fakturownia said the digital certificates used to access KSeF remained secure [8]. If both statements hold, the attacker's reach stops short of submitting or reading invoices inside the state system [7] [8].
Zaufana Trzecia Strona, a Polish security publication, reported that someone using the name "Fingerprint" sent its journalists screenshots of application directories, customer information and database dumps as proof of access [13]. Fingerprint claims 6 terabytes of invoices. Neither that figure nor the authenticity and full scope of the material has been independently verified [14]. Fakturownia is still working out how many customers were affected [2]. It is investigating with outside cybersecurity specialists and has reported the breach to Poland's cybersecurity and data protection authorities [10].
Fingerprint's earlier claims set the scale. Polish cyber officials said in August that the MyDr breach involved historical data that could relate to about 18.8 million people and more than 12,000 medical facilities [16]. Local authorities are investigating the Medyc intrusion; Medyc is developed by Qbusoft [17]. Taken at its word, Fingerprint is running a sustained campaign against Polish software vendors whose single system holds records for many downstream businesses or clinics [15]. The attribution so far rests on Fingerprint's own claims [15].
Digital Affairs Minister Krzysztof Gawkowski said on Tuesday that authorities were working to establish the circumstances of the attack [11]. "This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences," he said [12]. "The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity," Gawkowski said [18].
What to watch
- Fakturownia's count of affected accounts, and whether it confirms or disputes Fingerprint's 6-terabyte claim.
- A statement from Fakturownia on whether customer integration tokens were revoked and which algorithm produced the password hashes.
- Reports of forged bank-change invoices reaching Fakturownia customers' partners, the first sign the data is being used.