Threat intel
Fakturownia breach: what invoicing SaaS users must rotate
Polish invoicing platform Fakturownia lost account data, tokens and invoices in a 38-hour intrusion. What was taken and what to rotate and check now.
Fakturownia.pl, a Polish online invoicing and accounting platform used by more than 600,000 businesses, says an intruder was inside its systems from about 03:20 on September 27 to about 17:45 on September 28, 2026, and copied a large part of its database to their own servers. The company says the incident affects every account: user and company details, password hashes, session, API and integration tokens, bank account numbers, counterparty records and older invoices.
If you invoice through Fakturownia, you have work to do this week, and so do the firms that receive your invoices. The same applies to customers of any invoicing or accounting SaaS hit this way: the data is what a fraudster needs for a convincing "our bank account has changed" message, and the tokens open every system connected to the platform.
What was taken
The download ran from the oldest records forward and was cut off before it reached newer ones, which is why Fakturownia's incident page defines the scope by dates.
| Data | What was exposed |
|---|---|
| Accounts and users | Names, tax IDs (NIP), addresses, emails, phone numbers, for all accounts |
| Credentials | Password hashes, session tokens, API tokens, integration keys |
| Banking | Bank account numbers and payment information stored in the account |
| Counterparties | Name, NIP, address, phone and bank account, if added before October 16, 2024 |
| Invoices | Full content of invoices issued before March 22, 2021; line items before June 6, 2019; amounts from later invoices |
| Not taken | Payment card data, KSeF certificates, logins to banks |
Early reports summarised the invoice scope as "before 2023"; the later, detailed notice narrows it to the dates above. Polish media citing the company's update add that for roughly 2,250 accounts, all data from 2022 to 2026 was extracted, so a small group is far more exposed than the rest.
Poland's Ministry of Finance said on September 29 that it found no breach of KSeF, the national e-invoicing system, and no leak of data held there.
How it worked
Fakturownia has not published the root cause beyond "a vulnerability", and the accounts that exist do not fully agree, so treat the following as reported, not confirmed.
The attacker, who uses the name "Fingerprint", contacted the Polish security site Zaufana Trzecia Strona with screenshots of the application server, the client list and exported database records. According to that account, the way in was a time-based blind SQL injection. In this kind of injection the application returns no data or errors, so the attacker asks yes or no questions in SQL and reads each answer from how long the server takes to reply, extracting a secret one character at a time.
The secret reportedly extracted was the master key of the Ruby on Rails application. Rails uses that key (secret_key_base) to sign and encrypt session cookies, so the server trusts any cookie built with it. An attacker who holds it can forge a valid session cookie, and where the application deserializes cookie contents into Ruby objects, a crafted cookie can run code on the server. Niebezpiecznik reports a different first step, through invoice templates and the PDF generation library, ending with the same session signing key. Fakturownia's own timeline lists extra security controls added to its PDF generator at 02:35 on September 29.
Both versions end with a leaked signing key, after which every session, cookie and token derived from it is suspect. That explains why Fakturownia rebuilt its servers and replaced keys instead of only patching.
What the attacker and the company did
Fingerprint previously stole data from the Polish medical platforms MyDr and Medyc.pl. For Fakturownia, the actor claims to hold 6 TB of invoices. That figure has not been independently verified.
Blocking the first attacker IP at 13:35 on September 28 did not end the intrusion; access went on until about 17:45, and fixing the flaw at 18:01 closed it. The old API tokens were not revoked outright. They keep working from IP addresses each account used before, which avoids breaking integrations overnight but leaves the old keys alive.
On September 29 the company reported the incident to UODO (Poland's data protection authority), CERT Polska and the Central Cybercrime Bureau (CBZC), and it has since started sending breach notices to account owners. Digital Affairs Minister Krzysztof Gawkowski said those responsible are being pursued.
What to do
Tokens and bank details come first, because they enable silent access and payment fraud.
- Replace every API and integration token. In Fakturownia, generate new API keys and update them in each connected tool: your ERP, e-commerce store, CRM, payment gateway and anything built in-house. Then rotate the other side: integration keys that third-party systems hold for Fakturownia were in the stolen data too.
- Rotate KSeF credentials anyway. KSeF was not touched, but reissuing the tokens or certificates your integration uses costs little and removes the question.
- Check the bank account in settings. Compare the account number in your Fakturownia company settings and on invoice templates against your bank statement.
- Change the password and turn on two-step verification. The hashes can be cracked offline, so change the password anywhere you reused it, starting with the account's mailbox. Log out of all sessions and remove users you did not create.
- Warn your counterparties. Their names, tax IDs and bank details leaked from your account. Tell them in writing that your bank account has not changed and that any message saying otherwise must be confirmed by phone.
To check whether you were already hit, look at the access logs of each system that accepted a Fakturownia token, for requests between September 27 and the moment you rotated, from IPs you do not recognise. In your bank, review outgoing transfers since September 27 that were triggered by invoices, and any payee whose account number changed recently. In Poland, a number can be checked against the VAT payer register (the "white list"). Report suspicious SMS messages to CERT Polska by forwarding them to 8080.
Customers who process personal data through Fakturownia are data controllers in their own right. If the leak creates a risk for the people in your records, a notification to UODO is due within 72 hours of becoming aware of it. Fakturownia counts that from receipt of its notice email; a preliminary report can be filed and completed later.
The wider lesson for any invoicing SaaS
An invoicing platform holds real invoices with real amounts and the bank accounts both parties expect to pay. After a breach like this, expect payment redirection messages that quote a genuine invoice number and amount. Train accounts payable staff to treat any bank detail change as unverified until it is confirmed by a call to a number on file, never one in the message.
Keep an inventory of every token you have issued to or from a SaaS platform, which system holds it, and how to rotate it. Where the platform allows it, restrict API keys to known source IPs and give each integration its own key, so one leak does not require replacing everything.
If you want help mapping which systems trust your SaaS tokens, our attack surface management team can build that inventory, and security operations can watch for the payment fraud and token misuse that follow a breach like this. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: The Record, KSeF GPT, Fakturownia incident notice, Niebezpiecznik, Zaufana Trzecia Strona, Cyberscope, XYZ, Portal.Faktura.pl.