A TikToker tested a tax system with a fake condom invoice: it has no questions. And only a pharmacist saved the Polish PM’s office — and it’s clean tax record

KSeF Scam Invoices: The PM’s Office Didn’t Buy Condoms

In February 2026, a man walked into a pharmacy in a Polish shopping centre, bought a packet of condoms, and asked for the VAT invoice to be made out to the Chancellery of the Prime Minister. He gave the Chancellery’s tax number. He had no connection to it — no contract, no order, no relationship of any kind. Under rules that had taken effect two weeks earlier, none of that mattered. Had the pharmacist completed the request, the invoice would have been validated by the state and deposited in the Chancellery’s own records, and nobody working there could have refused it.

That is not a loophole. Poland’s Krajowy System e-Faktur routes every structured invoice to whoever’s tax identification number appears on it, and the workflow contains no step at which the recipient accepts or declines. Documents sent this way on purpose have earned a name in Polish practice: faktury scamowe, KSeF scam invoices. France switches on a comparable regime on 1 September 2026.

How a request at a pharmacy counter reaches a government ledger

KSeF became compulsory in phases — 1 February 2026 for taxpayers whose 2024 gross sales exceeded PLN 200 million, 1 April 2026 for the remaining VAT-registered businesses, and 1 January 2027 for micro-entrepreneurs. The production release, KSeF 2.0, went live with the first wave. Volume followed immediately: the Ministry of Finance reported over 87 million invoices from more than 345,000 entities in the first two months of mandatory operation.

In a clearance model, an invoice is not sent to a business. It is submitted to a central government platform, validated there, and then routed to a recipient identified only by the NIP written on the document. Three consequences follow, and none of them existed under invoicing by PDF and email:

  • Delivery is automatic and unconditional. The document lands in the recipient’s repository whether or not any transaction took place.
  • There is no accept-or-reject step. Nothing lets a recipient refuse a document before it is recorded against their tax number.
  • Corrective notes are gone. Errors, including a wrong NIP, are fixed only by the issuer raising a corrective invoice to zero. The recipient cannot correct a document issued against them.

A recipient can hide an unwanted document from their own view of the system. That is a display setting — reversible, invisible to the issuer, and it changes nothing about the document’s existence.

The video, and what happened to the man who filmed it

The pharmacy visit was staged. Tomasz Sidorczuk, a community activist from Bielsko-Biała better known locally for campaigning on cycling infrastructure, filmed the whole thing and posted it to TikTok, where it passed a million views inside a day and reached roughly 4.5 million by the end of the month.

Two facts about the incident matter more than the stunt. The invoice was never generated — the pharmacist declined to issue it. And the tax at stake was 89 groszy, under a quarter of a euro.

On 26 February 2026, Sidorczuk was questioned at the Silesian Customs and Tax Office in Katowice and charged with incitement to issue an unreliable invoice. He denies it and has said that if the case reaches court he intends to fight for acquittal; on the most recent reporting, charges have been presented but no indictment or verdict has followed.

His argument was never that the system can be broken into. It was that verification has quietly become the recipient’s job, at a volume nobody sized for. In a business processing thousands of documents a month, he said, it is bardzo łatwo przeoczyć fakturę wystawioną omyłkowo lub bez podstawy — “very easy to miss an invoice issued by mistake or without basis.”

One side says nothing is broken. The other is not arguing about the same thing.

Poland’s Ministry of Finance responded that the circulating material nie wskazuje na istnienie luki w KSeF — “does not indicate the existence of a gap in KSeF” — and gives no grounds to assert a risk connected with how the system functions. Public broadcaster Radio Kraków was blunter, treating the video as a stunt inflated beyond its worth, on the grounds that możliwość wystawienia faktury na dowolny NIP istniała od zawsze — “the ability to issue an invoice to any tax ID has always existed.”

Both statements are true, and both answer a question nobody asked. Writing someone else’s tax number on an invoice has never been hard. What changed is what happens afterwards.

Practitioners handling the inbound side describe the problem in operational terms rather than architectural ones. As Joanna Łuksza put it, wystawienie scamowej faktury nie zawsze jest proste do wykrycia — “issuing a scam invoice is not always simple to detect” — typically a document from a company the recipient has never dealt with, or for a transaction that never happened. Poland’s Ombudsman has raised a separate concern from a different direction: that the breadth of data gathered in KSeF may sit awkwardly with statutory protection of business secrets and with EU data-protection standards.

The disagreement dissolves once you separate issuing from delivery. Before KSeF, a fabricated invoice had to reach you — by post, by email, through a channel you controlled and could ignore. Under a clearance model it is validated by the state and placed directly into your tax records, with no point at which you can say no. The defence is right that issuing was always possible. It is answering an objection about delivery.

What Article 62 of the Fiscal Penal Code actually says

Coverage of the charges reported three different maximum penalties: three years, a floor of one year, and — attributed to a television journalist — up to eight. The statute settles it. Sidorczuk was charged under Article 18 § 2 of the Criminal Code, read with Article 20 §§ 1 and 2 and Article 62 § 2 of the Fiscal Penal Code of 10 September 1999 (consolidated text, Dz.U. 2025 poz. 633).

Article 62 § 2 provides for a fine of up to 720 daily rates, or imprisonment for a term not shorter than one year, or both. One year is the statutory floor, not the ceiling — and neither three years nor eight appears anywhere in the provision.

What sits immediately after it went unmentioned in the coverage entirely:

  • § 2a covers the same conduct where the tax arising from the invoice is of small value. It drops the one-year minimum, leaving a fine of up to 720 daily rates, or imprisonment, or both.
  • § 5 provides that in a case of lesser gravity, conduct under §§ 1–4 is punishable by a fine for a fiscal misdemeanour rather than as a fiscal offence.

The tax at issue was 89 groszy. Whether either provision applies here, and how incitement works where the invoice was never issued at all, are questions for the court and for a Polish fiscal-penal specialist — not conclusions to be drawn from reading a statute at a distance. But the gap between the reported exposure and the range the code sets out is wide enough that anyone working from the news figures is working from the wrong numbers.

What you can do when a scam invoice lands

KSeF 2.0 includes an abuse-reporting function: a business can flag a document it believes fraudulent for examination by the National Revenue Administration. Three limits are worth knowing before building a process around it.

  • Reports go one document at a time. There is no bulk submission.
  • The function is technical in character — the tax administration does not report back on what it finds.
  • You can track the status of your report. That is the extent of the visibility.

Where a wrong NIP is a genuine mistake rather than an attempt at fraud, the route is different and faster: contact the issuer, ask for a corrective invoice to zero, then a correctly addressed one. The distinction matters, because an abuse report aimed at what turns out to be a typo burns the only channel you have.

The failure mode worth designing against is mundane. Not a sophisticated attack — an invoice for a service nobody ordered, from a company nobody has dealt with, priced low enough and dated tightly enough to clear an approval queue on a busy week. The warning signs practitioners flag are unremarkable, which is exactly why they can be systematised: language errors in the service description, no reachable contact for the issuer, unusually short payment terms.

France goes live on 1 September 2026

France’s first obligation applies to every business regardless of size — the ability to receive compliant electronic invoices from 1 September 2026. Large and mid-sized enterprises must also issue from that date; smaller businesses follow on 1 September 2027. Invoices move through accredited platforms rather than one central state portal, so the architecture is decentralised in a way Poland’s is not. The property that produced the KSeF argument is the one both models share: a structured invoice addressed to your identifier arrives through a channel you do not control, and arrival is not consent.

Poland suspended financial penalties through the end of 2026, with enforcement beginning 1 January 2027. That has an underappreciated consequence for anyone watching from another jurisdiction — the incident rate visible today is the rate under conditions where mistakes are cheap. Belgium, live since 1 January 2026, moved to progressive penalties on 1 April 2026 once its tolerance period ended.

Two questions are worth settling before a mandate goes live rather than after. Who reviews inbound structured invoices, and does that person have authority to stop payment on a document already recorded against your tax number? And what internal signal separates a wrong-identifier error from an attempt at fraud, given that the remedies differ and only one of them is quick?

Frequently asked questions

Can I reject an invoice sent to my tax ID in KSeF?

No. Structured invoices are assigned to the buyer automatically on the basis of the NIP, with no accept-or-reject step, regardless of whether the transaction took place. You can hide the document in your own view of the system — reversible, and invisible to the issuer — but the document itself remains. Removal requires the issuer to file a corrective invoice to zero.

What should I do if a fraudulent invoice appears in my KSeF account?

Use the abuse-reporting function in KSeF 2.0 to flag it for the National Revenue Administration, one document at a time. If it looks like a simple error rather than fraud — a mistyped NIP, most often — contact the issuer first and ask for a correction to zero, which is faster. Pay nothing you cannot trace to a real order.

Does an invoice in my KSeF account mean I owe the money?

An invoice is a document, not proof of a debt. The obligation comes from the underlying transaction. The real risk is operational rather than legal: a document sitting in your records can be paid by mistake in a busy approval queue, and it still has to be handled correctly for VAT and reporting purposes. For a specific document and a specific exposure, take it to a tax adviser rather than a checklist.

Will France’s system work the same way as KSeF?

Not identically. France routes invoices through accredited platforms rather than a single central state portal. What carries across is that structured invoices addressed to your identifier arrive automatically through a channel you do not control — which is what makes the Polish experience worth reading before 1 September 2026.

When do penalties start in Poland?

Financial penalties for KSeF breaches are suspended through the end of 2026, with enforcement beginning 1 January 2027. That makes the rest of 2026 the window for fixing processes while errors are still cheap.