HomeSecurityInvoicely: Over 178,000 customer data files exposed

Invoicely: Over 178,000 customer data files exposed

In early October 2025, cybersecurity researcher Jeremiah Fowler discovered a publicly accessible database belonging to Invoicely, a Vienna-based invoicing and billing platform used by over 250,000 businesses worldwide.

Invoicely

The repository contained 178,519 files in XLSX, CSV, PDF, and image formats, each containing sensitive personal and financial information. Among the exposed documents were invoices, scanned checks, tax returns, and receipts from ride-sharing services. All of these revealed names, addresses, phone numbers, tax ID numbers, routing, and account information for healthcare providers, contractors, and corporate partners.

See also: T-Mobile: Interception of customer call and message data

The volume and variety of files amplified the potential consequences: from identity theft and spear-phishing to billing fraud and unauthorized financial transactions. Initial investigation showed that the database had no form of encryption or password protection, leaving it open to anyone with basic knowledge of its URL structure.

Fowler notified Invoicely, and the company restricted public access within hours. However, the duration of the exposure remains unknown, raising concerns about how many malicious users could have copied or monitored the data before it was restored.

Invoicely: Over 178,000 customer data files exposed

Invoicely: Data Exposure – Risks

The risks include submitting fake invoices using genuine invoice templates, fake tax returns using stolen IDs, and highly targeted phishing campaigns based on real transaction details. Website Planet analysts noted that the name of the database—'invoicely_backup_public'—suggests that it may have been intended for internal backup or third-party migration, but had been incorrectly configured for public access.

See also: Scattered Lapsus$ Hunters claim to have stolen over 1 billion Salesforce files

This mistake highlights recurring shortcomings in cloud storage governance among SaaS providers. Rapid deployment and scaling often override security controls. Fowler found no evidence of active exploitation, but the potential for undetected data collection remains significant.

The misconfiguration came from an unsecured Amazon S3 bucket, which was mistakenly set to “public-read” instead of restricted access. Attackers could enumerate buckets using tools like AWSBucketFinder or simple HTTP requests.

See also: SimonMed: Data breach affects 1.2 million people

Invoicely: Over 178,000 customer data files exposed

To mitigate such risks, SaaS providers must enforce strict access policies, automate storage controls , and adopt least privilege access principles when providing resources in the cloud.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS