Cyberattack on Polish medical software provider exposes patient data
Hackers exploited an SQL injection flaw in Polish medical platform Medyc, stealing patient data potentially covering 5 million patients, after the MyDr breach.
An attacker exploited an SQL injection vulnerability in Qbusoft's Medyc medical records platform in late August 2026 and exfiltrated an encrypted database archive; the intrusion was detected overnight September 9 and the flaw was patched the same day. Stolen data includes names, PESEL national ID numbers, addresses, and contact details, and an affected clinic says database scripts targeting medical tables make theft of treatment records highly likely. An actor named 'fingerprint', linked to the earlier MyDr breach affecting up to 19 million people, claimed records on 5 million patients and 8 million private photographs. Poland's cybercrime bureau is investigating, and the DPA ordered an audit after Qbusoft failed to report the incident to CERT Polska.
- SQL injection in Medyc API let attackers exfiltrate an encrypted database archive in late August.
- Stolen data includes names, PESEL numbers, addresses; medical records theft deemed highly likely.
- Actor 'fingerprint', linked to MyDr breach, claims 5 million patients' records and 8 million photos.
- Qbusoft failed to report to CERT Polska; Polish DPA ordered an audit and minister threatened sanctions.
Full article875 words · extracted from therecord.media · click to collapse
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months. Qbusoft, which develops the Medyc medical records and practice management platform, was breached after an attacker exploited an SQL injection vulnerability in August, according to a notification issued last week by one of the healthcare providers affected by the incident. SQL injection is a security flaw that allows hackers to trick a website into giving them access to information stored in its database. Medyc said Friday the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. The company said it had not confirmed the theft of medical records, but an affected healthcare provider said it was informed that Qbusoft had found evidence the attackers executed scripts targeting database tables containing medical information, making it “highly likely” that they also obtained some medical records. The Addiction and Psychiatric Treatment Center in the central city of Inowrocław said patients at its day treatment unit were affected and that potentially compromised medical information included hospital treatment records and discharge summaries. According to the center, an unauthorized person exploited an SQL injection vulnerability in Medyc’s application interface in late August and transferred an encrypted archive of a database outside Qbusoft’s systems. The intrusion was detected overnight on September 9. The center said the affected records covered patients treated by its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026. Some identifying information, including names and national identification — or PESEL — numbers, had been encrypted in the database, the center said. However, Qbusoft advised the healthcare provider to assume the attackers could easily decrypt the information. Qbusoft fixed the SQL injection vulnerability on the day the attack was discovered, according to the center. The company also restricted database permissions, rotated passwords and other technical credentials, and introduced additional monitoring. Qbusoft has not publicly commented on the investigation. Medyc said its infrastructure has faced repeated attack attempts in recent weeks and warned that some services could be temporarily unavailable. “Due to the intensity and frequency of attacks, the website may periodically run slower and access to some modules may be temporarily limited or unavailable,” the company said. “We are taking steps to protect our infrastructure and ensure the continuity of our services.” Medyc is a cloud-based platform used by Polish healthcare providers for electronic medical records, patient registration and scheduling, diagnoses, electronic prescriptions, sick notes and referrals, telemedicine, and administrative services. Digital Affairs Minister Krzysztof Gawkowski said Thursday that the Central Bureau for Combating Cybercrime was investigating the Medyc attack as part of a broader inquiry. He also criticized Qbusoft for not initially reporting the incident to CERT Polska or the national incident response team responsible for the healthcare sector. “In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced,” Gawkowski said. “Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk,” he added in a separate statement. Poland’s data protection authority said Friday that its president had ordered an audit of the company behind Medyc. Gawkowski said Saturday that Polish authorities had observed growing cybercriminal activity targeting healthcare organizations in recent weeks and were preparing regulations to strengthen protections for medical information. The proposals include mandatory security certification and restrictions on how private companies can process medical data, according to the minister. The Medyc intrusion came shortly after another major breach involving MyDr, a separate Polish healthcare software company. Polish authorities have said the MyDr incident potentially involved information relating to about 19 million people and approximately 12,000 healthcare organizations. MyDr develops software used by healthcare providers to manage medical practices and electronic records and connects providers to Poland’s nationwide electronic health platform, which supports services including electronic prescriptions and referrals. MyDr said it identified and removed the cause of the incident and introduced additional safeguards but has not publicly detailed the vulnerability used by the attackers. The Inowrocław treatment center affected by the Medyc incident was also among the organizations affected by the MyDr breach. Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the name “fingerprint,” which the publication previously linked to the MyDr breach, contacted it claiming responsibility for the Medyc intrusion. The purported attackers claimed to have obtained records concerning 5 million patients and 8 million private photographs. Zaufana Trzecia Strona said it could not independently verify those figures. The actor reportedly claimed that the operation was intended to expose weak cybersecurity rather than achieve financial gain. Polish broadcaster RMF FM separately reported that attackers connected to the MyDr breach were likely behind the Medyc breach. Polish authorities have not publicly attributed the Medyc breach to a particular individual or group, and the stolen information has not been publicly released. Investigation continues
Healthcare attacks
No previous article
No new articles
Daryna Antoniuk
is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.