Cyberattack on Fakturownia – data breach affecting 600,000 users
Fakturownia, a firm providing accounting systems, fell victim to a cyberattack. The breach includes user data and invoices from before 2023, but does not affect the KSeF or payment cards.

Attack on Polish invoicing system
Fakturownia, which supplies accounting systems to over 600,000 clients, was attacked by unauthorised users – Dziennik Gazeta Prawna reported on Tuesday. According to deputy prime minister and minister of digitalisation Krzysztof Gawkowski, the incident was reported to CERT Polska, and the services are working intensively to establish details.
Unauthorised access to Fakturownia's systems was discovered on Monday and confirmed by a company representative the following day. The attackers exploited a system vulnerability that gave them access to part of the infrastructure. The scope of the breach includes user account data, password hashes, bank accounts, payment information, and application keys and passwords – company employees said.
All users and their contractors whose data may relate to invoices issued before 2023 could be affected. The company assured, however, that the breach did not include data integrated with the KSeF (National e-Invoice System), other integrations with Fakturownia, or payment card information. Data from invoices issued after 2023 remained secure.
Gawkowski stated that "the perpetrators are being pursued and will face severe consequences". The incident was reported to both CERT Polska and the Central Bureau for Combating Cybercrime (CBZC), as well as to the head of the Personal Data Protection Office. Fakturownia is still establishing which clients were affected by the attack; notifications will be sent directly.
Editor-in-chief of the Trusted Third Party website Adam Haertel suggested that the attack on Fakturownia may have been carried out by the same perpetrators responsible for the data breach affecting approximately 19 million Poles from the MyDr systems and 5 million users of the Medyc application by Qbusoft. The series of incidents prompted deputy prime minister Gawkowski to appeal to the private sector to increase spending on cybersecurity protection.
The company recommended users change their Fakturownia account password, as well as the associated email address and other services where the same password may have been used. Recommendations include enabling two-factor authentication, checking account settings, and reviewing the list of users with access to the account. Special attention should be paid to bank account numbers provided on invoices.
Fakturownia warned against potential phishing messages, SMS texts, and calls from people impersonating banks, government offices, courier companies, or contractors. Users should not share passwords, verification codes, BLIK codes, or payment card data – neither in messages, on pages accessed via links, nor over the phone. The company never requests passwords in such situations.
Source: Dziennik Gazeta Prawna