In the space of five days, one of Poland’s most popular invoicing platforms reported a breach affecting every account, and Google released an AI model built to find software vulnerabilities on its own. Google also paused part of its bug bounty programme because AI-generated reports were overwhelming it. AI isn’t creating new hackers. It is giving each attacker tools to work faster and at a larger scale, with less skill. That changes what „good enough” security means for every company.

The Fakturownia incident: what happened

According to the company’s official statement, an unauthorised person had access to Fakturownia’s systems from about 03:20 on 27 September until about 17:45 on 28 September 2026. During that time they copied a large part of the database. The company says the incident affects every account. It has reported the breach to the Polish data protection authority (UODO), CERT Polska and the police cybercrime unit (CBZC), and is analysing it together with CERT Polska.

The data that may have been copied includes:

  • company and user details (names, tax IDs, addresses, emails, phone numbers)
  • bank account numbers, including IBAN/SWIFT
  • password hashes
  • API tokens and integration keys
  • invoice and payment data (full or partial, depending on the date)
  • contractors, products and price lists

KSeF certificates, bank login details and card data were not affected, according to the company.

This is why business SaaS platforms are such attractive targets. A single breach exposes thousands of companies at once, along with their customers, payments and the keys that connect them to other systems.

To be clear: nothing so far links the Fakturownia incident to AI. The cause hasn’t been made public and the investigation is ongoing. We mention it because it shows clearly what is at stake, not because of how it happened.

AI is changing the economics of cyberattacks

Most attacks are still built from familiar steps. AI makes each step cheaper:

  • Reading large codebases. Models can review thousands of files in minutes and highlight the code most likely to contain flaws.
  • Finding vulnerabilities. Models can suggest likely bugs and help confirm whether they can be exploited.
  • Automating reconnaissance. Mapping a company’s domains, exposed services, employees and tech stack no longer takes days.
  • Phishing and social engineering. Fluent, personalised messages in any language, including flawless Polish, at almost no cost.
  • More attempts for less work. An attacker can now try a hundred targets in the time one used to take.

None of this requires a new kind of attacker. It just means the same people can do much more.

Google shows it’s no longer theory

On 30 September 2026, Google announced Gemini 4 Argon, the first model in its Gemini 4 family. Google says the model can independently search for critical software vulnerabilities, verify them and prepare patches. During testing, Google says, it found a previously unknown critical vulnerability in medical software.

Notably, Google isn’t releasing it to everyone. The first users are trusted cybersecurity specialists, with API customers and Google AI Ultra subscribers to follow later. Google is giving defenders a head start because a model that can find vulnerabilities on its own would be just as useful to an attacker.

Timeline from 27 September to 1 October 2026: Fakturownia unauthorised access begins and ends, the breach is reported to authorities, Google announces Gemini 4 Argon, and Google pauses part of its open-source bug bounty
Three events in five days. No link between the Fakturownia incident and AI has been confirmed.

AI is also creating problems for defenders

A day later, on 1 October, Google paused new product vulnerability submissions to its Open Source Software Vulnerability Reward Program (OSS VRP). The reason was a flood of AI-generated reports describing bugs that didn’t exist or couldn’t be exploited. Supply-chain reports and the Google Cloud programme remain open. The maintainers of curl and the Linux kernel have reported the same problem.

This is „AI slop” in security. Generating a convincing report takes seconds, but every report still needs a human expert to check it. When fake reports pile up, real vulnerabilities wait longer in the queue. Automation helps attackers more than it helps the people who have to review the results.

What this means for a regular company

You don’t need your own AI security lab. You need to get the basics right and stop treating them as optional:

  1. MFA everywhere it’s available, starting with email, admin panels and finance tools.
  2. Rotate API keys and tokens regularly, and immediately after any supplier reports a breach.
  3. Least privilege: every person, service and integration gets only the access it needs.
  4. Monitor logins and alert on unusual locations, times and volumes.
  5. Back up, and test restores. A backup you’ve never restored is only a hope.
  6. Keep everything updated: systems, libraries and plugins. AI makes known vulnerabilities faster to exploit.
  7. Segment access so that one compromised account can’t reach everything.
  8. Have an incident response plan: who does what in the first hour, and who you notify.
  9. Train your team on phishing, with realistic AI-generated examples.
  10. Run regular security tests, including penetration tests and code reviews, not just a single audit.

If you use Fakturownia, follow the company’s own advice: set a new password, change it anywhere you reused it, generate new API keys for your integrations, check your account settings and user list, and confirm any request to change bank account details by phone, using a number you already know.

The most important change

The risk isn’t that „AI will attack our servers”. The more accurate version is less dramatic and more important: AI lowers the cost of carrying out a cyberattack. Security measures that were „good practice” a few years ago, like MFA, key rotation, least privilege and tested backups, are now a necessity. The same tools that help attackers are starting to help defenders too, but only for companies that use them.

Want to know how exposed your applications and integrations are? Talk to the Fireup team about a security review.

Sources