Polish accounting software firm Fakturowania suffers major data breach affecting user accounts
Fakturowania reported a cyberattack that exposed account details, invoices and banking information of its Polish users, and the incident has been handed to CERT Polska and other authorities.
Fakturowania, a provider of accounting software in Poland, confirmed that a cyber-intruder used a vulnerability in its platform to obtain unauthorized access to a range of data, including user and contractor account details, invoice information dated before 2023, password shortcuts, bank account numbers and application keys. The company detected the incident on Monday and posted a notice on its website on Tuesday, stating that no payment-card information or KSeF integrations were breached and that invoices issued after 2023 were unaffected.
Authorities such as CERT Polska, the Centralne Biuro Zwalczania Cyberprzestępczości and the President of the Office for Personal Data Protection have been notified, and investigations are ongoing to determine the full scope of affected clients. Fakturowania has advised all users to reset passwords, secure their email accounts, enable two-step verification and monitor for phishing attempts impersonating banks or the service. The breach follows earlier leaks attributed to the same perpetrators, including data from MyDr and Medyc applications.
