Qbusoft, the developer of the Medyc medical records and practice management platform used by healthcare providers across Poland, was breached after an attacker exploited an SQL injection vulnerability in the application interface in late August, according to a notification issued by one of the affected providers. Medyc said on Friday that the attackers obtained names, national identification (PESEL) numbers, home addresses, phone numbers and email addresses. The company has not confirmed the theft of medical records, but the Addiction and Psychiatric Treatment Centre in Inowrocław said it was informed that Qbusoft had found evidence the attackers executed scripts targeting database tables containing medical information, making it "highly likely" that some records were taken. The centre said records covering patients treated in its day treatment unit between July 2024 and August 2026 were in scope, that an encrypted archive of a database was transferred outside Qbusoft's systems, and that the intrusion was detected overnight on 9 September. Qbusoft fixed the flaw on the day it was discovered, restricted database permissions and rotated credentials. Poland's data protection authority ordered an audit of the company, and Digital Affairs Minister Krzysztof Gawkowski criticised Qbusoft for not reporting initially to CERT Polska; the Central Bureau for Combating Cybercrime is investigating.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-29 |
| Source | The Record |
| Reliability | Tier 2 |