Cyberattack on major Polish invoicing platform exposes customer data
Fakturownia says an attacker exploited a flaw and accessed account data, bank details, and invoices for Polish businesses.
Fakturownia, used by more than 600,000 Polish businesses, said an attacker exploited a vulnerability and accessed account data, password hashes, bank details, tokens, and pre-2023 invoices. Payment cards and KSeF, Poland’s national e-invoicing system, were not compromised, according to the company and the Finance Ministry. The firm detected the intrusion, rotated credentials, and notified Polish authorities. An actor named Fingerprint claimed 6 terabytes of invoices and also claimed the MyDr and Medyc breaches; the Fakturownia haul is unverified.
- Fakturownia serves over 600,000 businesses and detected unauthorized server access this week.
- Exposed data may include password hashes, bank details, tokens, and older invoices.
- Poland’s tax platform KSeF was reviewed and found not breached.
- Fingerprint claimed 6TB of invoices; volume and authenticity remain unverified.
- Fingerprint previously claimed MyDr and Medyc healthcare software intrusions.
Full article483 words · extracted from therecord.media · click to collapse
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners. Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected. The potentially compromised information includes user and company account data, password hashes, bank account information, authentication and integration tokens, and information belonging to customers and business partners. The attacker may also have accessed invoices issued through Fakturownia before 2023, the company said. Payment card data and information stored through the company’s integrations were not affected. The breach has drawn scrutiny because Fakturownia integrates with the National e-Invoicing System (KSeF), a platform operated by Poland’s tax administration that many businesses are required to use. The Finance Ministry said Wednesday that a review found no breach of KSeF’s security and no leak of data held by the system. Fakturownia separately said digital certificates used to access KSeF remained secure. Fakturownia said it detected the unauthorized access on Monday and subsequently blocked the attacker, began rotating passwords and application keys, and brought new servers online. It is investigating the incident with outside cybersecurity specialists and has reported the breach to Poland’s cybersecurity and data protection authorities. Polish Digital Affairs Minister Krzysztof Gawkowski said Tuesday that authorities were working to establish the circumstances of the attack. “This is another cyber incident affecting a private company. Those responsible are being pursued and will face serious consequences,” he added. Polish cybersecurity publication Zaufana Trzecia Strona reported that an attacker using the name “Fingerprint” contacted its journalists and provided material purporting to show access to Fakturownia’s infrastructure, including screenshots of application directories, customer information and database dumps. The attacker claimed to have stolen 6 terabytes of invoices. That figure, as well as the authenticity and full scope of the purportedly stolen material, has not been independently verified. Fingerprint has also claimed responsibility for recent breaches involving Polish healthcare software providers MyDr and Medyc. Polish cyber officials said in August that the MyDr breach involved unauthorized access to historical data that could relate to approximately 18.8 million people and more than 12,000 medical facilities. Separately, local authorities are investigating the intrusion involving Medyc, software used by healthcare providers that is developed by Qbusoft. “The recent attacks show that the private sector needs to increase its investment and efforts to strengthen cybersecurity,” Gawkowski said.
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.