A data breach involving VosFactures, an online invoicing software published by Factuali, has raised concerns among its users. The breach was identified by Fakturownia, a Polish technical provider, who alerted Factuali on Tuesday, September 29. According to a report by FrenchBreaches on Thursday, October 1, account data, customer and supplier information, and part of the generated documents may have been accessed. The breach occurred a month after the implementation of an electronic invoicing reform, which requires all VAT-subject businesses to receive invoices in an approved format since September 1, 2026. VosFactures is one of the approved platforms. Factuali confirmed that its servers are separate from those of Fakturownia, and its environment is hosted in a cloud certified by SecNumCloud by the ANSSI, the national cyber security agency. The company states it has found no signs of intrusion on its side and that credit card data and electronic invoicing services managed directly by Factuali were not affected. According to Fakturownia, the breach may have exploited a flaw in the tool that converts invoice templates into PDF files, allowing access to configuration files containing application keys and technical identifiers. These keys could have been used to execute commands on multiple servers and read a replica of the production database. The scenario is similar to a hacking incident involving Brevo in mid-September, where a single compromised key threatened over 100,000 sites. However, Factuali has not provided details on the number of affected accounts, the number of documents, or the duration of access. The publisher's announcement does not mention any report to the CNIL, the French data protection authority. In Poland, a hacker known as "Fingerprint" detected the intrusion on Monday, September 28. Krzysztof Gawkowski, the Polish vice premier in charge of digital affairs, confirmed the attack. The hacker previously attacked MyDr and Medyc, two Polish medical services, with stolen data concerning more than 18 and 5 million people, respectively. Fakturownia claims to have over 600,000 customers, both in Poland and abroad. The hacker claims to have downloaded 6 terabytes of invoices, though this figure has not been independently verified. This volume could store millions of PDF invoices. For Polish customers, Fakturownia mentions access to password fingerprints, bank accounts, and invoices issued before 2023, though it is unclear if this scope applies to French accounts. This leak adds to a series of data breaches in late September. A hacker claims to be selling the files of 16.2 million French people attributed to Alaxione, a publisher of medical appointment software. At the same time, the ANSSI detailed how hackers accessed the tax office website. Earlier this year, data had leaked from the ANTS, the agency managing identity documents and driver's licenses. In August, Bloctel may have allowed nearly 3 million phone numbers to leak. Factuali has invalidated all API codes on Thursday, October 1, which are used to connect VosFactures to merchant sites or accounting software. Users are advised to generate new codes and change their passwords. They should also be cautious of any emails requesting changes to bank account numbers, as scammers could use customer and supplier lists to create convincing fake invoices.