Nearly 180k records exposed in billing platform breach – here’s what we know

  • A researcher has found almost 200k personal records exposed
  • It looks to belong to a billing platform, Invoicely
  • This leaves anyone impacted at risk of fraud or identity theft

A publicly exposed database left without encryption or a password and containing 178,519 files has been discovered by cybersecurity researcher Jeremiah Fowler. In the sampling of the exposed files, he reported seeing personally identifiable information (PII) like names, addresses, numbers, tax ID, and more.

By analyzing the records, the researcher theorized the databases belong to small business billing platform, Invoicely – although it’s not certain if the database is owned/managed directly by the company, or if it is run by a third party.

A serious concern when PII is involved is the threat of identity theft, since criminals will attempt to use your details to take out loans or credit cards. The added danger with financial details or invoices is that threat actors may replicate or impersonate customers or business partners using fake invoices or financial dealings.

Official IdentityForce® | Identity Theft Protection – save up to 68% annually

Many people don’t know how to protect their ID. Don’t be one of them. Get your ID Action Plan here. Get a personalized step-by-step Action Plan & ID Safety Score based on YOUR dark web hits.View Deal

Elevated risks

The inclusion of financial information like tax documents represents an opportunity for threat actors to create multiple different attacks, including fraud, social engineering, or spear-phishing attacks – or even lead the criminals to higher value targets through their business dealings.

The researcher also outlines the risk of fraudulent tax filings, with approximately 6,000 tax returns filed using stolen identities in 2025 – creating complicated situations for taxpayers who are then left picking up the pieces.

“My advice to organizations that develop and provide invoice and accounting platforms, applications, or services is to limit the collection and retention of personal data when possible,” said Fowler.

“Encrypt sensitive information so that it is not human readable; that way, if there is a data exposure, encryption adds an additional layer of security. While not impossible to decrypt, properly encrypted files remain extremely difficult to access without the correct credentials.”

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You might also like

Read more @ TechRadar

Latest posts

The Steam Frame is a surprising new twist on VR

Here’s me wearing the Steam Frame, Valve’s new VR headset. Valve is about to launch a new virtual reality headset, and with it, a comprehensive...

Valve’s new Steam Controller might be my dream controller

The new controller at Valve’s HQ. One of the best parts of the Steam Deck is its many different controls, and how you can customize...

Here are the best Kindle deals right now

The current Kindle Colorsoft may soon be overshadowed by the upcoming Kindle Scribe Colorsoft. | Image: The Verge When it comes to finding a device...

Valve has no news about Steam Deck 2

Valve has just announced its biggest hardware push that it’s arguably ever made — a living room game console called the Steam Machine, a...

Valve has stopped manufacturing its Index VR headset

Valve has just announced the Steam Frame, its new VR headset that can play games streamed directly from your PC using a dedicated streaming...

Valve is welcoming Android games into Steam

You can think of the just-announced Steam Frame as a wireless VR headset for your PC, or a Steam Deck for your face. But...

OpenAI says the brand-new GPT-5.1 is ‘warmer’ and has more ‘personality’ options

OpenAI is releasing GPT-5.1 today, an update to the flagship model it released in August. OpenAI calls it an “upgrade” to GPT-5 that “makes...

Valve thinks Arm has ‘potential’ for SteamOS handhelds, laptops, and more

A Steam Frame with a transparent case. Valve won’t talk about a Steam Deck 2. It probably wants to keep the attention on its just-announced...

How the Steam Frame compares to other VR headsets

Valve just announced the Steam Frame, a new standalone VR headset that can both stream games from a PC and play games locally thanks...

We tried Valve’s new VR headset, PC, and controller — ask us anything!

The Verge’s Sean Hollister on the left and Jay Peters on the right. Hi! I'm Jay Peters, a senior reporter here at The Verge. I'm...