How to rotate Fakturownia API keys after the breach?

Following the data breach detected on September 28, 2026, store owners must rotate all external Fakturownia API tokens. Temporary IP restrictions are not enough to secure your integrations. Learn how to replace your keys in WooCommerce and Shoper without causing any store downtime.

10 min read 12 views
How to rotate Fakturownia API keys after the breach?

Last updated: 6 October 2026

If your WooCommerce or Shoper store issues invoices through Fakturownia, replace every Fakturownia API key you have pasted into an external tool, and every key to another system that you saved in your Fakturownia account settings. An integration that still works is not the same as a safe one. According to Fakturownia's statement, existing keys now only work from IP addresses used before, but they were copied by an unauthorised party.

Below is a map of what to replace, in what order so your store keeps issuing invoices, and how to confirm the old key no longer opens anything.

What we know about API keys (as of 5 October 2026)

Fakturownia detected the breach on 28 September 2026. Unauthorised access lasted from 27 September, around 03:20, to 28 September, around 17:45. The company listed the detailed scope in Update no. 1 of 1 October 2026 at fakturownia.pl/incydent (Polish).

For a store owner, these findings matter most:

  • API tokens and integration keys stored directly in account settings were taken, in full, depending on the integrations used.

  • Session identifiers and password hashes were taken (passwords were not stored in plain text).

  • During the night of 28–29 September Fakturownia replaced customers' API tokens. Existing keys work only from IP addresses previously used by the account's users.

  • KSeF certificates were not taken, nor was data from Fakturownia's own integrations configured under "Integracje i dodatki" (Integrations and add-ons).

  • Poland's Ministry of Finance stated on 29 September 2026 that the incident does not concern data held in KSeF, the national e-invoicing system.

Fakturownia numbers each update to its statement. Before you start, check whether a newer one has been published.

Why "the integration works" doesn't mean "the key is safe"

An API token is effectively a password with no username and no second factor. Whoever has it can send requests on behalf of your account, within whatever the API allows: reading and creating invoices, clients and products. Treat a leaked token exactly like a leaked password.

Restricting keys to known IP addresses is a sensible stopgap during an incident, not a fix. Stores on shared hosting often reach the internet from an IP address shared with many other sites on the same server. And you don't know how long the provider will keep that restriction in place.

There is also a second direction that's easy to miss. The breach covers not only keys to Fakturownia (pasted into your store) but also keys from Fakturownia to other systems that you saved in its settings, such as a webhook token used for stock synchronisation. Those have to be revoked on the side of the system that issued them.

Map: which Fakturownia API keys and integration keys to replace

Where the key lives Example In scope of the breach? What to do Fakturownia token in the WooCommerce plugin "Fakturownia WooCommerce" plugin (WP Desk), "API Token" field yes new token in Fakturownia, paste into the store, delete the old one Webhook token saved in Fakturownia stock sync Fakturownia → WooCommerce (product:update) yes, if saved in account settings new webhook token in the plugin, replace it in Fakturownia Third-party apps in Shoper price or stock updates from Fakturownia to Shoper yes (token from "Kod autoryzacyjny API") new token, paste into the app's configuration "Fakturownia" app in Shoper Fakturownia's own integration depends on where it's configured confirm with Fakturownia (shoper@fakturownia.pl) Order integrators BaseLinker, Sellasist and similar yes contact the provider first, then rotate Your own scripts and automations .env, Zapier, Make, a local MCP server yes a separate new token for each tool Other systems' keys saved in Fakturownia any key entered in the account's integration settings yes revoke at the source, generate a new one, enter it in Fakturownia Password and sessions owner and user accounts password hashes and session IDs new unique password and two-step verification

The rule from Fakturownia's statement: its own integrations under "Integracje i dodatki" need no action. Anything else that uses an API token gets rotated.

API key rotation step by step, without store downtime

Order matters. If you delete the old token first and only then start looking for where to paste the new one, your store won't issue a single invoice in the meantime.

  1. Take inventory. In Fakturownia go to Ustawienia → Ustawienia konta → Integracja → "Zobacz ApiTokeny" (Settings → Account settings → Integration → View API tokens). Note which tool uses each token. Any token you can't attribute gets deleted at the end.

  2. Ask your integration providers. Fakturownia recommends contacting external providers before generating new keys. Some have their own procedure or sequence.

  3. One token, one integration. Generate a separate token for each tool and give it a clear name, e.g. woocommerce-store-2026-10. Next time, you switch off one channel instead of all of them.

  4. Paste the new token and test it on a real flow. Place a test order and check that the invoice was created. In the WooCommerce plugin you can enable debug mode under WooCommerce → Settings → Integrations → Fakturownia; errors go to the WooCommerce logs.

  5. Only now delete the old token from the list in Fakturownia.

  6. Replace webhook tokens and any other system keys that were saved in Fakturownia.

  7. Change your password to a new, unique one, and change it anywhere else you reused it. Turn on two-step verification, which Fakturownia offers and recommends.

  8. Review your account: the list of users with access and the bank account number printed on your invoices.

WooCommerce: also check your store's REST API keys

The plugin isn't the only place with keys. Under WooCommerce → Settings → Advanced → REST API you'll see every access key to your store, its permissions and when it was last used. Revoke keys you don't use and any you handed to external services if they could have been stored in Fakturownia. Where read access is enough, set "Read" rather than "Read/Write".

Shoper: tell Fakturownia's integration apart from third-party apps

In the Shoper admin panel go to Dodatki i integracje → Moje aplikacje (Add-ons and integrations → My apps). Open the configuration of every app that connects to Fakturownia. If you see a field for an API token, that token comes from Fakturownia and needs replacing. This is how, for example, apps that automatically update prices and stock levels from Fakturownia to Shoper work.

How to check that the old key no longer works

The simplest check for non-technical users: the old token is gone from the list in Fakturownia and the integration runs on the new one. That's enough.

If you want a technical check, send the request from a terminal, not a browser (a URL with a token would stay in your history):

curl -s "https://YOUR-DOMAIN.fakturownia.pl/invoices.json?api_token=OLD_TOKEN"

You're expecting an authorisation error, not a list of invoices. One catch: since old keys only work from previously used IP addresses, a test from your laptop proves nothing. The meaningful test is one run from the store's server, the address the key was used from before.

Keys aren't everything: invoices, bank accounts and GDPR

Fake invoices and bank account swaps. Fakturownia warns that fraudsters may know invoice amounts and which invoices are unpaid. Confirm every request to pay into a new account by phone, using a number you know from earlier dealings, and check business accounts against the Polish VAT whitelist (biała lista). Suspicious text messages can be forwarded to CERT Polska at 8080.

Reporting the breach to UODO. For your clients' and customers' data, you are the controller and Fakturownia is the processor. Under Article 33 GDPR you have 72 hours from becoming aware of the breach; Fakturownia indicates this usually runs from receipt of its e-mail of 1 October 2026. A late report is still required, with the reason for the delay. After logging in, Fakturownia provides a partly pre-filled form for UODO, the Polish data protection authority.

Whether a report and notification of individuals (Article 34 GDPR) are needed in your case is your assessment as controller. For your specific situation, consult a lawyer or a data protection officer.

Limiting the damage of the next breach, at any provider

A breach can happen in any system. What you can decide is how much one stolen key can do.

  • A separate token for every integration, with a name and creation date.

  • The smallest permissions that work. A store that only reads data doesn't need write access.

  • Rotation on a calendar, e.g. every six months, not only after an incident.

  • Keys in a password manager, not in e-mails, chats or notes.

  • One page listing who holds a key to what. In today's rotation, that page saves the most time.

  • A review of KSeF permissions. KSeF certificates weren't part of the breach, but this is a good moment to review granted permissions in the KSeF Taxpayer Application and remove unused ones.

Summary

After the Fakturownia breach, replace Fakturownia API keys in every external integration: the WooCommerce plugin, third-party Shoper apps, order integrators and your own scripts. Also revoke keys to other systems that were saved in your account settings. Work in order: inventory, new token, test, and only then delete the old one. In parallel, change your password, turn on two-step verification, confirm every bank account change by phone, and assess whether you need to report to UODO.

How we approach this at Biurko

We build Biurko from the perspective of a developer who runs a sole proprietorship (JDG) himself and uses it every day, so "what if this key leaks" is a question we ask when designing every integration. KSeF certificates and tokens are stored encrypted in our database. The connection to KSeF is based on a permission you grant in KSeF and can revoke yourself at any time in the KSeF portal or via Profil Zaufany. Tokens for AI assistants (MCP) come with permission controls, and irreversible actions require human confirmation.

If you're switching invoicing software before 1 January 2027, you can try Biurko on the FREE plan: no card required, with unlimited sending to KSeF.

FAQ

Do I need to replace my API keys after the Fakturownia breach?

Yes, if you use an API token outside Fakturownia's own integrations under "Integracje i dodatki". According to the 1 October 2026 statement, API tokens were taken in full, and old ones now only work from previously used IP addresses. Generate a new token for each integration, paste it in, and only then delete the old one.

My WooCommerce integration still works. Does that mean it's safe?

No. It works because the old key is still allowed from your store's IP address. The key has nevertheless been copied. Generate a new token in Fakturownia, paste it into the plugin's "API Token" field, test with a dummy order and delete the old one. Replace the webhook token too if you sync stock levels.

Does the Fakturownia breach affect KSeF?

According to Fakturownia, KSeF certificates were not taken. The Ministry of Finance stated on 29 September 2026 that the incident does not concern data held in KSeF. Still, it's a good moment to review the permissions granted in the KSeF Taxpayer Application and remove any you don't use.

Do I have to report the Fakturownia breach to UODO?

For your clients' data you are the controller, so you assess the risk and decide on reporting (Article 33 GDPR, 72 hours). After logging in, Fakturownia provides a partly pre-filled form. A late report is still required, with a justification for the delay. If in doubt, consult a lawyer.

How do I check that my old Fakturownia token has stopped working?

The simplest way: the old token no longer appears under Settings → Account settings → Integration, and the integration runs on the new one. Run any technical test from the store's server, since old keys only work from previously used IPs. A request with the old token should return an authorisation error, not invoices.

Tags

#cybersecurity #invoicing software
Share

Previous article

Looking for Fakturownia alternatives? Ask 7 security questions

Stay in the loop

An email when we publish a new article — and nothing else.

We respect your privacy. Unsubscribe at any time.

Cookies

We use only essential cookies. Visit statistics are kept on our server, with nothing saved on your device. Website Policy