Cyberattack on Polish medical software provider exposes patient data
Hackers exploited an SQL injection flaw in Polish medical platform Medyc, stealing patient data potentially covering 5 million patients, after the MyDr breach.
An attacker exploited an SQL injection vulnerability in Qbusoft's Medyc medical records platform in late August 2026 and exfiltrated an encrypted database archive; the intrusion was detected overnight September 9 and the flaw was patched the same day. Stolen data includes names, PESEL national ID numbers, addresses, and contact details, and an affected clinic says database scripts targeting medical tables make theft of treatment records highly likely. An actor named 'fingerprint', linked to the earlier MyDr breach affecting up to 19 million people, claimed records on 5 million patients and 8 million private photographs. Poland's cybercrime bureau is investigating, and the DPA ordered an audit after Qbusoft failed to report the incident to CERT Polska.