DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Fakturownia Data Breach: Invoices and Emails Stolen

Poland's invoicing platform Fakturownia confirmed on 1 October that an attacker copied its database, covering every account: invoice data, bank details, and reported email addresses. I run AliasFleet, an email-alias service that gives every website its own forwarding address, so one vendor's breach poisons one address instead of your identity. This breach shows why that matters. The stolen data is worse than contact details. It is everything needed to send you a fraudulent invoice that looks exactly like the real one.

What Fakturownia confirmed

The attacker had roughly 38 hours: from about 03:20 on 27 September to 17:45 on 28 September 2026. In that window they copied a substantial portion of the company's database to external servers. Fakturownia's first security update went out on 1 October. Individual GDPR notifications began the same day.

The story did not start with the company. On 29 September, Polish security outlet Zaufana Trzecia Strona reported an attack attributed to someone using the handle "Fingerprint", and the early scale claims came from the alleged attacker. Then the company confirmed unauthorised access itself, and Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski confirmed the cyberattack publicly. That sequence matters: the incident no longer rests on an attacker's word. Both the company and the government say it happened (Poland Insight's writeup lays out the timeline).

The reported scope is every Fakturownia account, with an important qualifier from the company: that does not mean every data field was exposed for every account. The reported data categories are names, tax identification numbers, addresses, email addresses and phone numbers of users and businesses, plus bank account numbers, payment information, password hashes, application system keys, and invoices issued before 2023.

Some things were explicitly not taken. Full invoice body text from 22 March 2021 onward was reported as not copied, and neither were contractor records added from 16 October 2024 onward. Poland's National e-Invoice System, KSeF, was not affected, confirmed separately by the Ministry of Finance. Payment-card data and bank login credentials were never stored by the platform, so there was nothing to leak. Passwords were stored as hashes, not plaintext.

The response so far: access blocked on 28 September, credentials and keys rotated, infrastructure rebuilt, API tokens reissued. The incident was reported to the data protection office (UODO), CERT Polska, and the Central Bureau for Combating Cybercrime. The company says it will notify affected customers directly.

The fraud this data was built for

Most breaches hand attackers a spam list. This one hands them a forgery kit.

Think about what sits in that database together. Real invoice amounts. Real seller and buyer identities. Real bank account numbers. And the email addresses and phone numbers of the people on both sides of those invoices. An attacker holding all of that does not need to guess what a convincing fraud looks like. They can reconstruct it.

The classic move is the bank-detail switch. Your supplier's "accounting department" writes to say they have changed banks, please update your records, here is the new account number. The email references a real invoice you are actually expecting, for the real amount, with the real names. The usual advice, look for typos and check the sender, fails here because there is nothing wrong with the content. The details are genuine. Only the destination account is the attacker's.

Poland Insight makes exactly this point: invoice data makes it easier to impersonate a business partner and request payment to a different account, and there is no confirmation yet that anyone has done so. The fraud has not been observed. The capability is what is new.

This is why the email addresses matter more here than in a typical leak. They are not the prize. They are the delivery mechanism for the invoice data. A phone number lets the attacker follow up a fake invoice with a reassuring call. An email address lets them send the forgery to the exact person who pays the real invoices. Each piece is ordinary. Combined, they are a business-email-compromise starter kit aimed at small businesses that rarely have a finance team double-checking payment changes.

Where the reporting gets thin

Honesty requires saying what is not solid yet.

Email addresses are in the copied data according to Undercode News, which phrases it as "reportedly includes". Poland Insight's company-sourced list says "user and customer account information" without naming email addresses explicitly. So email exposure is reported by one English outlet and consistent with everything else, but not independently confirmed by a second source. I have not read Fakturownia's original Polish notice, only the English reporting of it, and I am not going to pretend otherwise.

No victim count has been published, so do not trust any number attached to this breach today. Nobody has verified the "Fingerprint" claim beyond the initial report. CERT Polska's monitoring had not seen the data publicly posted at the time of reporting. Good news with a short shelf life: stolen data can be used privately, sold quietly, or published later. Absence of a leak site is not absence of risk.

What to check this week

Fakturownia's own advice is sensible, so start there. Change your account password, and change it everywhere else you reused it, because the password hashes are out there and reused passwords are how one breach becomes five. Switch on two-factor authentication. Then check the settings the attacker would most like to have quietly changed: the bank account numbers on file and the list of users with access to your account.

Next, set a rule for invoice mail. Any request to change payment details gets verified through a previously known contact channel, not by replying to the email that asked. Call the number you already have, not the one in the signature. This is the company's own recommendation and it is the single highest-value habit coming out of this breach.

Treat unexpected invoices with extra care for the next few months, especially ones that reference real past amounts or real past transactions. Those details no longer prove legitimacy. They are exactly what the attacker has.

Check Have I Been Pwned and switch on its breach notifications so the next one reaches you directly. The longer version of the response checklist is in our breach response guide. And watch for mail impersonating Fakturownia itself: password-reset lures and "urgent security update" emails are the standard second wave after a breach like this.

One alias per supplier

Here is the structural point. The advice above, verify through a known channel, works but depends on you being careful every time. An email alias moves the check into the address itself.

Give each supplier and each invoicing platform its own alias. Then a "please update our bank details" email arriving at the wrong alias is fraud by construction. Your supplier was never given that address. No link inspection, no header forensics. The alias did the detecting before you finished the subject line. That is the same mechanism our leak-tracing guide describes: the To field names the source, and a mismatch names the lie.

I run AliasFleet, which does exactly this: one alias per website, forwarding to your real inbox, killable in one click. The docs explain the mechanics, and the free tier covers 10 active aliases. If you want the full picture first, read what an email alias is.

Two honest limits. An alias would not have stopped this theft; nothing a customer does stops the breach itself. And if the attacker compromises the actual supplier and emails the correct alias, the To-field check passes, so aliases shrink the attack surface rather than removing it. What they do is make the common case, a forged invoice from a lookalike sender, fail loudly instead of slipping through.

Top comments (0)