A significant data breach at Fakturownia, a major online invoicing platform in Poland, has potentially exposed sensitive information belonging to users, their customers, and business partners. The breach occurred when an unknown attacker exploited a vulnerability in the system, allowing unauthorized access to servers used by over 600,000 businesses. While the exact number of affected customers is still under investigation, compromised data could include account details, password hashes, bank account information, and integration tokens. However, payment card data and information stored through integrations were reportedly not impacted.
The incident has drawn attention due to Fakturownia's integration with the National e-Invoicing System (KSeF), a crucial platform for many businesses in Poland. The Finance Ministry has asserted that KSeF's security remains intact with no data leaks from their system. Fakturownia assured that digital certificates for accessing KSeF are secure. In response to the breach, the company swiftly blocked the attacker, initiated password rotations, and deployed new servers. They are collaborating with external cybersecurity experts and have informed the relevant Polish authorities.
Polish Digital Affairs Minister Krzysztof Gawkowski emphasized the seriousness of this cyber incident, stating that those responsible will face significant consequences. An attacker known as 'Fingerprint' has claimed responsibility for the breach and provided evidence suggesting access to Fakturownia's infrastructure, though these claims are yet to be verified.
This incident highlights the ongoing cybersecurity challenges facing the private sector in Poland, particularly in light of recent attacks on other software providers such as MyDr and Medyc. These events underscore the urgent need for increased investment and effort to bolster cybersecurity measures across all sectors.

