Cyberattack on major Polish invoicing platform exposes customer data
Fakturownia says an attacker exploited a flaw and accessed account data, bank details, and invoices for Polish businesses.
Fakturownia, used by more than 600,000 Polish businesses, said an attacker exploited a vulnerability and accessed account data, password hashes, bank details, tokens, and pre-2023 invoices. Payment cards and KSeF, Poland’s national e-invoicing system, were not compromised, according to the company and the Finance Ministry. The firm detected the intrusion, rotated credentials, and notified Polish authorities. An actor named Fingerprint claimed 6 terabytes of invoices and also claimed the MyDr and Medyc breaches; the Fakturownia haul is unverified.