
Episode notes
Fakturownia, a Warsaw-based cloud invoicing and accounting platform used by more than 600,000 businesses, has confirmed that an attacker exploited a flaw in its PDF-from-template generation, obtained server access, and over about 38 hours of access copied a large part of its production database. The company says every account is affected. France's VosFactures, which runs on the same platform, has confirmed indirect impact.
Timeline (Polish local time, per the company). Sunday 27 September, ~03:20 — unauthorised access begins. Monday 28 September, 13:35 — attacker's IP blocked (detection); ~17:45 — access ends; 18:01 — vulnerability fixed; evening — keys and passwords rotated, traffic moved to rebuilt servers, old servers shut down; 23:10 — customer panel locked; overnight — all customer API tokens replaced. Tuesday 29 September — reported to Poland's data protection authority (UODO), CERT Polska and cybercrime police; public statement 16:15. Thursday 1 October — individual notifications begin; update confirms the incident "concerns every account".
What was taken. In full: company and user details (names, tax numbers, emails, phones), bank account numbers including IBAN/SWIFT, salted password hashes, API tokens and integration keys, session IDs, and bank balances where the bank connection was active. By date cut-off (oldest-first download, interrupted; the company says cut-offs may vary by a dozen or so days): full invoices before 22 March 2021, invoice line items before 6 June 2019, counterparties added before 16 October 2024, warehouse documents before 14 July 2023, most export/import files generated up to 6 March 2026, and invoice amounts and descriptive fields across the whole period. About 2,250 accounts lost everything from 2022–2026. Not taken: KSeF e-invoicing certificates, bank logins and card data (not stored), and invoice contents from 22 March 2021 onward other than amounts, descriptive fields and additional-party data. Poland's national e-invoicing system was not breached (Ministry of Finance). No CVE. An actor calling itself "Fingerprint" claimed the attack and 6 TB of invoices; both are unverified claims. No ransom demand.
Lessons. Stolen invoices are the raw material for invoice-redirection fraud: use call-back verification for every bank-detail change and dual approval for new payees. Inventory and be ready to rotate every API key connected to your accounting platform. Apply retention limits (APP 11.2). Under the Notifiable Data Breaches scheme, a supplier breach can still be your obligation to assess. Write prompt, full breach notification into supplier contracts. MFA, unique passwords, and sign out all sessions after a provider breach.
Visit www.kinsoft.com.au to talk through your security and IT needs.
Sources: The Record; Fakturownia incident page (fakturownia.pl/incydent); Niebezpiecznik; Sekurak; Zaufana Trzecia Strona; CyberDefence24; cyberscope.pl; PIT.pl (Ministry of Finance statement); Cyberattaque.org (VosFactures).
