The Fakturownia data breach is a reminder that an invoicing platform holds far more than invoices. According to reporting on the incident, every account on the Polish service was copied, and invoice data and email addresses were taken. For the businesses that rely on it, and for the clients named on their invoices, that is a lot of personal and commercial detail in one place.
This post summarizes what has been reported, explains who should pay attention, and sets out practical steps. Details are still emerging, so treat figures from early coverage as reported claims rather than final findings.
What was taken in the Fakturownia data breach
The core claim is that the attacker copied data from all accounts on the platform. The reported haul includes invoice data and email addresses. Coverage of the incident also says the attacker exploited a vulnerability, and that the service has more than 600,000 customers.
Other reports add detail that is worth noting, with the caveat that it comes from secondary coverage:
- Polish media reported that the company confirmed a data leak but said it did not cover data integrated with KSeF (the Polish national e-invoicing system) or payment card information.
- Poland's digital affairs minister, Krzysztof Gawkowski, publicly said on 29 September 2026 that the company had suffered a cyberattack.
- One report cites a figure of 6 terabytes of stolen data and links the attack to a actor called Fingerprint, which has also been tied to a leak from the MyDr service. Another outlet reports that this actor says it does not want a ransom. These are claims, and none of them should be read as confirmed.
- A post from the Polish security outlet Niebezpiecznik says keys, tokens and information about contractors were also exposed. That would matter for any connected systems.
Because the situation is developing, the safest assumption is that everything stored in your account may have been copied.
Who is at risk: business owners and their clients
The obvious group is the account holder: freelancers, small companies and accountants who issue invoices through the platform. Their login emails, company details and billing history may now be in someone else's hands.
The less obvious group is everyone on the other side of those invoices. An invoice typically names a buyer, an address, a tax number, an amount and a date. If a platform is breached, your clients and suppliers are exposed even though they never created an account. They may not know the platform was used at all, and they may never receive a direct notice.
That second-order exposure is what makes invoicing platforms a valuable target. One compromise reveals a whole network of business relationships, not just one organization.
Why stolen invoice data fuels convincing phishing
Generic phishing is easy to spot: wrong name, vague request, odd sender. Invoice data removes those tells. A criminal who knows who you buy from, roughly how much you pay, and what an invoice normally looks like can write a message that fits your real routine.
Typical abuse looks like this:
- A fake "corrected invoice" with a new bank account number, sent to a client who regularly pays you.
- A message claiming a payment failed, with a link to a spoofed login page.
- A request to "confirm" company details, aimed at collecting more information for fraud.
Because the emails reference real transactions, recipients tend to lower their guard. This is the same pattern seen when business data is leaked after other incidents. For examples of how stolen data gets posted and monetized, see our coverage of the BYOD ransomware claim over 700GB of Franklin Empire data, where the significance lies in what the data can be used for.
What This Means For You
If you use Fakturownia, assume your account data was part of the copy and act accordingly. If you have ever been invoiced by someone who uses it, expect a higher chance of targeted emails that mention real invoices.
The risk is mostly indirect. A breach like this rarely causes harm on its own; the harm comes later, when the data is used to make fraud look legitimate. That gives you time to put defenses in place now.
What to do now and how to store less personal data
If you are an account holder:
- Change your password, and change it anywhere else you reused it. Use a unique password from a password manager.
- Turn on two-factor authentication where it is offered.
- Revoke and regenerate any API keys or tokens connected to your account, especially given reports that keys and tokens were exposed.
- Follow the company's official guidance and announcements rather than links in emails.
- Tell your clients that phishing attempts referencing your invoices are possible, and agree on how you will communicate any change of bank details.
If you receive invoices or pay suppliers:
- Treat any invoice-related email with suspicion, even if it mentions a real transaction.
- Verify bank account changes by phone using a number you already have, not one from the email.
- Do not click links in payment reminders; go to the service directly.
- Watch for lookalike sender domains.
To reduce future exposure:
- Store only the client details you genuinely need on invoices and in contact records.
- Delete old records you no longer need to keep, within the limits of your legal and tax obligations.
- Avoid putting sensitive notes in free-text invoice fields.
- Use a separate email address for business tools, so a leak does not expose your main inbox.
The less personal data a platform holds about you and your clients, the less there is to leak.
Key takeaways
The Fakturownia data breach shows how one compromised service can expose a business and its entire client base. Change your passwords, enable two-factor authentication, and treat every invoice-related email with suspicion until you have verified it independently. To see how stolen business data is used and exposed in other incidents, read our report on The Gentlemen ransomware group listing HBS Group, and keep an eye on official updates as the investigation develops.




