An attacker exploited an SQL injection vulnerability to infiltrate Qbusoft, the developer of Medyc, a cloud-based system for electronic medical records and practice management used across Poland's healthcare sector. The breach occurred in August, though notification came only last week from affected healthcare providers.
The compromised data includes names, national identification numbers, home addresses, phone numbers and email addresses. While Medyc initially said it had not confirmed the theft of medical records, the Addiction and Psychiatric Treatment Center in Inowrocław indicated that evidence suggests attackers accessed database tables containing medical information, making it "highly likely" that clinical records were also obtained.
The Inowrocław facility reported that its Day Treatment Unit for Addiction Treatment saw patient records from July 2024 through August 2026 potentially compromised. The unauthorized access occurred in late August when someone exploited the SQL injection flaw in Medyc's application interface and transferred an encrypted database archive outside Qbusoft's systems. The intrusion was discovered on the night of September 9.
Although some identifying information had been encrypted in the database, Qbusoft advised the healthcare provider to assume attackers could decrypt it. The company patched the vulnerability on the day of discovery, restricted database permissions, rotated credentials and added monitoring. Medyc has reported facing repeated attack attempts in recent weeks, warning that services may experience temporary unavailability.
Investigation continues
Digital Affairs Minister Krzysztof Gawkowski announced Thursday that the Central Bureau for Combating Cybercrime was investigating the incident as part of a broader inquiry. He also rebuked Qbusoft for failing to report the breach to CERT Polska or the healthcare sector's incident response team.
In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced.
Krzysztof Gawkowski
Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk.
Krzysztof Gawkowski
Poland's data protection authority ordered an audit of Qbusoft on Friday. Gawkowski said Saturday that authorities had detected escalating cybercriminal activity targeting healthcare organizations and were developing regulations to strengthen protections for medical information, including mandatory security certification and restrictions on how private firms handle medical data.
Healthcare attacks
The Medyc breach follows a separate major incident at MyDr, another Polish healthcare software company. Polish authorities have indicated the MyDr breach potentially exposed information on approximately 19 million people and roughly 12,000 healthcare organizations.
MyDr provides software for managing medical practices and electronic records and links providers to Poland's nationwide electronic health platform, which enables electronic prescriptions and referrals. The company said it identified and removed the incident's cause and added safeguards but has not publicly disclosed the vulnerability exploited.
The Inowrocław treatment center affected by the Medyc breach was also among those impacted by the MyDr incident. A person or group using the name "fingerprint," previously linked to the MyDr breach by Polish cybersecurity publication Zaufana Trzecia Strona, claimed responsibility for the Medyc intrusion, stating they obtained records for 5 million patients and 8 million private photographs. The publication could not independently confirm these figures.
The purported attackers said the operation aimed to expose weak cybersecurity rather than generate profit. Polish broadcaster RMF FM reported that actors connected to the MyDr breach were likely responsible for the Medyc attack. Polish authorities have not publicly attributed the breach to any specific individual or group, and the stolen data has not been publicly released.



