Major Polish Invoicing Platform Fakturownia Suffers Data Breach, Attacker Claims 6TB Stolen
Poland's prominent online invoicing service, **Fakturownia**, has disclosed a significant data breach, potentially exposing sensitive information belonging to over 600,000 businesses and their customers. An unidentified attacker exploited a system vulnerability, raising concerns across the Polish business landscape and prompting official investigations.
# Fakturownia Breach: A Deep Dive into Poland's Latest Cyber Incident
**Fakturownia**, a leading online invoicing platform in Poland serving over 600,000 businesses, has confirmed a data breach following unauthorized access to its servers. The incident, which came to light earlier this week, has triggered a thorough investigation and raised questions about the security of integrated financial systems.
## Scope of the Compromise
The company is still assessing the full extent of the breach, but potentially compromised data includes user and company account information, password hashes, bank account details, authentication and integration tokens, and data belonging to customers and business partners. Invoices issued through **Fakturownia** before 2023 may also have been accessed. Crucially, **Fakturownia** has stated that payment card data and information stored via its third-party integrations remain unaffected.
## KSeF Integration and Government Response
The breach's implications are magnified by **Fakturownia**'s integration with the National e-Invoicing System (**KSeF**), a platform managed by Poland's tax administration and mandatory for many businesses. The Ministry of Finance has since confirmed that a review found no breach of **KSeF**'s security or any data leak from the system itself. **Fakturownia** also assured users that digital certificates used to access **KSeF** remain secure.
Polish Digital Affairs Minister **Krzysztof Gawkowski** addressed the incident, stating that authorities are actively working to establish the circumstances of the attack. He emphasized, "This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences."
## The 'Fingerprint' Connection
Polish cybersecurity publication **Zaufana Trzecia Strona** reported that an attacker operating under the alias "**Fingerprint**" contacted their journalists, providing purported evidence of access to **Fakturownia**'s infrastructure. This evidence included screenshots of application directories, customer information, and database dumps. The attacker claimed to have exfiltrated 6 terabytes of invoices, though this figure and the full scope of the stolen material have not been independently verified.
Notably, "**Fingerprint**" has also claimed responsibility for recent breaches targeting Polish healthcare software providers **MyDr** and **Medyc**.
## Broader Implications for Polish Cybersecurity
These recent attacks underscore a concerning trend in Poland's private sector. The **MyDr** breach, reported in August, involved unauthorized access to historical data potentially affecting 18.8 million individuals and over 12,000 medical facilities. Separately, an investigation is ongoing into the **Medyc** intrusion, affecting software developed by **Qbusoft** and used by healthcare providers.
Minister Gawkowski's comments reflect the urgency of the situation: "The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity."
## Remediation and Ongoing Investigation
Upon detecting unauthorized access on Monday, **Fakturownia** swiftly blocked the attacker, initiated password and application key rotations, and deployed new servers. The company is collaborating with external cybersecurity specialists and has reported the breach to Polish cybersecurity and data protection authorities.