Newsify Today

Article content

Fakturownia Data Breach: Hackers Stole Client Records

2K

On September 28, 2026, the Fakturowni accounting service detected unauthorized access to its servers by a hacker operating under the alias "Fingerprint." The breach lasted from approximately 3:20 AM on September 27 until about 5:45 PM on September 28. According to an update released on October 1, attackers copied a significant portion of the database onto their own servers.

The compromised data includes account details for all users and their business counterparts (contrahents), along with invoices issued prior to March 2021, invoice line items from before June 6, 2019, and client information added before October 16, 2024. Specific financial records stolen included full text of certain invoices, payment details such as bank account numbers, VAT amounts in net/gross terms, and system credentials including API keys, session tokens, and password fragments.

The company confirmed that while it revoked all user API keys due to security concerns, the hackers did not manage to access data related to KSeF integrations or credit card information. Despite this partial success for attackers, cybersecurity expert Adam Haertle noted that unlike other sectors where false invoices can be generated, accounting firms must provide accurate records in a breach scenario.

The hacker previously targeted medical companies MyDr and Qbusoft before attacking Fakturowni. While the stolen data poses significant risks to businesses regarding their client lists and transaction histories, there is some indication the attacker does not intend to publish these documents publicly.

Trend: fakturownia