Your Software Vendor Got Hacked. Is Your Data in the Pile?
Late last month, a Polish invoicing platform called Fakturownia told its customers that attackers had gotten into its servers. The company serves more than 600,000 businesses. According to The Record, the exposed data includes company account details, password hashes, bank account details, login and integration tokens, customer and partner information, and older invoices.
Here is the part that matters for you: none of those 600,000 businesses did anything wrong. They paid a software company to handle their invoices, and that company got hit. Their information was stolen anyway.
That is vendor risk, and it is one of the most overlooked problems I see in small businesses around Southern Arizona.

You Are Only as Safe as Your Vendors
Think about every company that holds a piece of your business: your accounting software, your invoicing tool, your payroll provider, your CRM, your website host, your email platform, your cloud storage, even the company that manages your phones. Each one keeps copies of your data. Each one has logins that connect to your other tools.
It works like a house with a great front door lock. You can spend money on the lock, but if you hand spare keys to ten different companies, you are depending on all ten of them to keep those keys safe.
Attackers know this. Why break into thousands of small businesses one at a time when you can break into one vendor and collect all of them at once?
What Actually Gets Stolen in a Vendor Breach
Your business data
Invoices, customer names, bank details, and contracts. In the Fakturownia case, that included information about the customers of the businesses using the platform, not just the businesses themselves. Your customers’ data can leak through a company they have never heard of.
Passwords and login tokens
Stolen password hashes can be cracked, especially weak or reused passwords. Tokens and API keys are even more dangerous because they act like a pre-approved badge: whoever holds one can often get into connected systems without typing a password at all.
Details for the next scam
Real invoice details make a fake email look completely real. A criminal who knows who you pay, how much, and when can send a convincing “we changed our bank account” message. This often shows up weeks or months after the breach, long after the news cycle has moved on.
Why Small Businesses Get Caught Off Guard
Most owners I talk to cannot list every software tool their team uses. Someone signed up for a free trial, someone connected a tool to the company email, and nobody wrote it down. Those forgotten accounts do not get updated, do not get reviewed, and often still have an ex-employee’s login attached.
Then a breach notice shows up, and you have to answer a simple question: what did we put in there? Many businesses cannot answer it.
What You Can Do This Week
- List your vendors. Write down every company that stores your data or connects to your systems. Check your credit card statements for subscriptions, since that is where the forgotten ones hide.
- Mark the top five. Circle the ones that hold money, customer data, or employee data. Those get attention first.
- Turn on strong sign-in everywhere. Use multi-factor authentication on each account, and give every vendor a unique password stored in a password manager.
- Find and trim integrations. Look at what is connected to what. Remove API keys and app connections you no longer use, and rotate the ones you keep.
- Ask three questions. What data do you hold about us, how will you tell us if you are breached, and how do we get our data out if we leave? A good vendor answers these quickly.
- Watch for follow-up scams. If a vendor reports a breach, treat any payment change request from anyone as suspicious until you confirm it by phone using a number you already have.
- Keep your own copy. Make sure your key records are backed up outside the vendor’s system, so one bad day on their side does not become a bad day on yours.
If Your Vendor Reports a Breach
Do not panic, and do not ignore it. Change the passwords for that account and anything that shares the password. Revoke and replace any API keys or connected apps. Check for strange logins or sent messages. Then warn your team and your customers if their information was involved. The faster you rotate the keys, the less time an attacker has to use them.
The Bottom Line
You cannot stop a vendor from being hacked. You can control what you store with them, how well their door to your account is locked, and how fast you react when something goes wrong. Knowing who holds your data is the first step, and most businesses have not taken it.
Not sure who holds your data?
We help small businesses map their vendors, lock down accounts with staff security training, and set up secure data backups you control. See our small business cyber security solutions, or book a complimentary visit.
Related: why your MFA needs to be stronger and endpoint protection. More on our blog, and a good spam and virus filter helps catch the follow-up scams.
Send us a message
Have a question about your vendors or want help getting a list started? Send us a note.
Sources: The Record; This Week in Security.
— Nemuel Cruz, Incognito Cyber Security


