Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Attackers used SQL injection to steal Polish patient identities from Qbusoft's Medyc medical software.
Attackers stole personal data from Polish medical-software maker Qbusoft by exploiting an SQL injection flaw in its Medyc clinic platform on August 22-23, 2026, and moving an encrypted database archive off its systems. Qbusoft confirmed theft of names, PESEL national ID numbers, home addresses, phone numbers, and email addresses, but said medical-documentation theft is not confirmed. A clinic using Medyc said the vendor advised treating the encrypted data as easily decrypted and that hospital discharge summaries were highly likely taken. Qbusoft removed the flaw after detecting the attack on September 8-9, rotated secrets, and notified authorities; Poland's data protection office ordered an audit amid media reports of up to five million people affected.