Security incident - statement of 29 September 2026

Published on 30 September 2026. We will update this page as soon as we establish anything new.

On 28 September 2026 we detected unauthorised access to the servers of the invoicing system on which InvoiceOcean runs. As a result of the incident, an unauthorised person had visibility of user account data, contractor data and documents generated through the service.

We understand that such news may be worrying, which is why we want to give you all the information we currently have. We also explain what you can do to protect your data further. At the same time we can confirm that the incident did not affect data held within our integrations and add-ons.

What happened?

An unauthorised person managed to exploit a vulnerability in the system, which resulted in unauthorised access to part of the data. After detecting the event, we blocked that person's access, started rotating keys and passwords and launched new application servers. Together with external security specialists we are continuing to analyse the situation.

What we know at this point:

What have we done?

What data may have been affected?

Based on our findings so far, the unauthorised person may have had access to the following data:

If further analysis brings new findings, we will update this statement without delay.

What do we recommend?

To give your account additional protection, we recommend that you:

What may the consequences be? Stay alert

It is possible that in the near future you will receive e-mails, text messages or phone calls from people impersonating well known institutions - a bank, a public authority, a courier company, InvoiceOcean or your own contractors. Such messages often create time pressure and push you to act quickly. Please:

We are still establishing which customers are affected by the leak. We will notify each of them directly in the near future.

We are sorry for this situation. The security of your data is our priority and we are investigating the matter with full commitment. We will keep publishing further findings on this page.

Frequently asked questions

Were my data affected by the InvoiceOcean breach?

We are still establishing which customers are affected. The unauthorised access may have covered account data of all users, their contractors and invoices issued before 2023. We will notify every affected customer directly.

What data may have been leaked?

Company and user account data including password hashes, session tokens, API tokens and integration tokens, bank account numbers and payment data, contractor data and, in part, invoice data, as well as system keys and passwords of the application.

Were passwords leaked in plain text?

The data that may have been accessed contains password hashes, not passwords in plain text. We still recommend changing your password, and changing it anywhere else you used the same one.

Were my invoices leaked?

The unauthorised access may have covered invoices issued before 2023. To the best of our knowledge, invoices issued after 2023 were not leaked as a result of the incident.

What should I do now?

Change your password, change the password of the e-mail account linked to your account, enable two-step verification, review the bank account number shown on your invoices and the list of users with access, and revoke and reissue your API tokens if you use integrations.

Is it safe to keep using the service?

The service is running. After detecting the incident we blocked the intruder's access, launched new application servers and started rotating keys and passwords, and we are continuing the analysis with external security specialists.

Do you have questions about the incident?

If you want to check whether this concerns your account, or you need help securing it, write to us. Questions about the processing of your personal data can be sent the same way.

Contact us