What to do and what to watch for after the Fakturownia data breach. A guide for our customers

Last updated: 2.10.2026

In one paragraph

The breach happened on the servers of Fakturownia, the invoicing service we use. It did not affect our own systems. The copied database included customer records and invoice amounts. The biggest risk is not someone logging into your account, but a fraudster who knows exactly how much you owe and to whom, and uses that to redirect a payment. The defence is simple: always confirm a bank account number by phone, using a number you already know, never one from the message itself.

1. What happened and whose fault it is

  • On 28 September 2026 Fakturownia sp. z o.o. discovered a breach. The attacker copied a large part of the fakturownia.pl database, a service used by more than 600,000 businesses in Poland.
  • Every account in Fakturownia was affected. We are one of its customers, like hundreds of thousands of other companies.
  • Our websites, applications, servers and e-mail were not affected. Software built or delivered by EVO-CODE® was neither the target nor the route of the attack.
  • Fakturownia reported the breach to the Polish Data Protection Authority (UODO), CERT Polska and the police. We reported it to UODO as the company that entered your data into that system.
  • Fakturownia's official statement with the full list of data: https://fakturownia.pl/incydent

2. What data may have been copied

From the invoices we issued:

  • company name or full name, VAT ID, address, e-mail address and phone number (for customers added to the system before 16 October 2024);
  • invoice amounts for the whole period: net, VAT, gross, how much was paid and how much remains due;
  • the full content of invoices issued before 22 March 2021;
  • for bank transfers: date, amount, title and the account number the payment came from.

Not affected: payment card data and bank login details, because Fakturownia does not store them.

3. Five fraud scenarios to expect

Scenario 1: "We have changed our bank account." An e-mail or letter on company letterhead, quoting a real invoice number and a real amount, asking you to pay to a new account. This is the most dangerous one, because everything in it is correct except the account number.

Scenario 2: a fake payment reminder. "Invoice no. ... is overdue, pay immediately or the case goes to debt collection." Time pressure and threats are the hallmark of fraud.

Scenario 3: a call "from the bank" or "from Fakturownia". The caller knows your company name, amounts and dates, so they sound credible. They ask you to log in, read out an SMS code, install a "security app" or make a "test transfer".

Scenario 4: phishing by e-mail or SMS. "Unlock your account", "verify your payment details", "download your invoice", with a link to a page that looks like Fakturownia, your bank or our company and asks for a login and password.

Scenario 5 (private customers): a visit or call "from the contractor". Someone claims to represent our company, an installer or the funding programme and asks for an extra payment, an "inspection fee" or access to your home.

4. What to do: a checklist

Right away

  1. Save our phone number from earlier contact or from our website. That is the number you will use to confirm anything that looks suspicious.
  2. If you set a password in the Fakturownia customer panel and used the same password elsewhere (e-mail, bank, shops), change it everywhere it was the same.
  3. Turn on two-factor authentication in your e-mail and online banking if it is not on yet.

With every invoice and every transfer

  1. Our bank account number does not change. Treat any notice of a change as fraud until we confirm it by phone on a number you already know.
  2. Check the account on the Polish Ministry of Finance VAT whitelist: https://www.podatki.gov.pl/wykaz-podatnikow-vat-wyszukiwarka. Enter the issuer's VAT ID and compare the account number with the invoice.
  3. Do not pay under pressure. A genuine business partner does not demand payment "within the hour".
  4. Do not reply to a suspicious message. Call us separately, on the known number.

With calls and messages

  1. If "the bank", "the tax office", "Fakturownia" or "our company" calls and asks for a password, a code, an app installation or a transfer: hang up and call back on the number from the institution's official website.
  2. Do not click links in unexpected messages. Go to your bank and to Fakturownia by typing the address yourself.
  3. Check the sender's address. Our e-mails come only from our own domain. Fakturownia writes only from fakturownia.pl. Watch out for addresses with a typo or an extra word.
  4. Suspicious SMS messages can be forwarded free of charge to CERT Polska at 8080.

If something happens

  1. A transfer to a fake account: call your bank immediately and ask them to stop the transfer. Minutes count.
  2. Report the case to the police and keep all messages as evidence.
  3. Let us know: use the contact details below. It helps us warn other customers and update our report to the authority.

5. What you do not need to do

  • You do not need to change your bank account number. Knowing an account number does not allow anyone to take money from it.
  • You do not need a new e-mail address. Caution with messages is enough.

6. Your rights

As a data subject you may ask us at any time what data we process about you and request correction or erasure (Articles 15 to 17 GDPR). We respond within one month. You may also lodge a complaint with the President of the Polish Data Protection Authority, ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.

For data held about you as a user of the Fakturownia service, the contact is Fakturownia's Data Protection Officer: iod@fakturownia.pl.

7. Contact us

E-mail and phone are listed in our notice page. We reply during office hours.

We will update this guide as new facts emerge. The date of the last change is at the top of the page.