SQL Injection Attack Leads to Patient Data Breach at Polish Medical Software Provider
Hackers exploited a vulnerability in Qbusoft’s Medyc platform, exposing patient data, following a recent breach at MyDr.
Breach Details
Hackers stole patient data from Qbusoft, a Polish medical software provider, following exploitation of a security vulnerability in its Medyc platform, which handles patient registration, records, and prescriptions. This incident occurs weeks after a separate breach at MyDr, a Warsaw-based company, exposed records of nearly 19 million individuals. The Medyc breach involved unauthorized access to personal information, including names, PESEL numbers, addresses, and contact details.
Qbusoft’s Response
Qbusoft confirmed the breach in a statement published on September 25, noting that attackers accessed data stored on its infrastructure. The company reported the incident to multiple authorities, including the Central Cybercrime Bureau and the Personal Data Protection Office, and disclosed repeated attack attempts over the preceding week. Qbusoft stated that its systems experienced performance issues due to the attacks, with some modules temporarily unavailable. The company has not disclosed the exact number of affected individuals.
Clinic’s Role
A psychiatric treatment center in Inowrocław, which uses Medyc, provided additional details. Forensic analysis revealed that an unauthorized party exploited an SQL injection vulnerability in the application interface between August 22 and 23, 2026, to extract an encrypted database archive. The breach was detected on the night of September 8–9, with data export commands lacking time limits. The clinic estimated that all patients treated at its addiction day unit between July 1, 2024, and August 23, 2026, were impacted.
Data Exposure Risks
While the database stored names and PESEL numbers in encrypted form, the vendor advised the clinic that the encryption was weak, allowing attackers to access the data in plain text. Attackers also executed scripts against medical data tables, potentially obtaining hospital discharge summaries. The clinic warned that stolen health information could be misused for identity theft, harassment, or fraudulent medical services.
Security Measures Taken
Qbusoft addressed the vulnerability on the day it was discovered, restricting database permissions, rotating credentials, and implementing continuous monitoring.
Dispute Over Reporting
A dispute emerged over reporting procedures, as Poland’s Deputy Prime Minister and Minister of Digital Affairs noted that Qbusoft had not notified CERT Polska or CSIRT CeZ, despite claiming to have alerted authorities.
Data Protection Audit
The data protection authority has initiated an audit of the Medyc provider, citing reports of up to five million affected individuals in Poland.
Healthcare Infrastructure Risks
The incident highlights ongoing risks in healthcare infrastructure, with attackers leveraging SQL injection flaws to exfiltrate sensitive data.
