Cyberattack on major Polish invoicing platform exposes customer data
What happened
Fakturownia said earlier this week that an unidentified attacker exploited a vulnerability in its systems and gained unauthorized access to servers. The breach has drawn scrutiny because Fakturownia integrates with the National e-Invoicing System (KSeF), a platform operated by Poland’s tax administration that many businesses are required to use.
The Finance Ministry said Wednesday that a review found no breach of KSeF’s security and no leak of data held by the system. One of Poland’s major online invoicing platforms suffered a data breach (an incident in which data leaves an organisation without permission) that may have exposed information belonging to its users, their customers and business partners.
The company, whose service is used by more than 600,000 businesses, is still trying to determine how many customers were affected. The potentially compromised information contains user and company account data, password hashes, bank account information, authentication and integration tokens, and information belonging to customers and business partners.
The attacker may also have accessed invoices issued through Fakturownia before 2023, the company said. Payment card data and information stored through the company’s integrations were not affected.
Key facts
- The Finance Ministry said Wednesday that a review — found: no breach of KSeF’s security and no leak of data held by the system
- The potentially compromised information — includes: user and company account data, password hashes, bank account information, authentication and integration tokens, and information belonging to customers and business partners
Sources & evidence
- The Record Reporting source
Cyberattack on major Polish invoicing platform exposes customer data ↗
https://therecord.media/poland-cyberattack-invoice-software