VYPR
breachPublished Sep 30, 2026· 1 source

Poland Investigates Second Major Healthcare Software Hack, Potentially Exposing 5 Million Records

Polish authorities are investigating a cyberattack on Qbusoft, a vendor of medical software, which may have exposed up to 5 million patient records, weeks after a similar breach at MyDr affected 19 million Poles.

Polish officials are currently investigating a significant cyberattack targeting Qbusoft, a domestic vendor specializing in medical software. The company's flagship product, Medyc, is at the center of the incident, which authorities fear could have exposed the personal and medical data of up to 5 million individuals. This latest breach follows closely on the heels of a massive cyberattack on MyDr, another major medical records software provider in Poland, which impacted nearly 19 million citizens – roughly half of the country's population.

Qbusoft acknowledged the attacks in a statement, describing them as "frequent and repeated attack attempts by cybercriminals" over the past week. While the company stated that the theft of medical records has not been definitively confirmed, it warned patients to be vigilant against suspicious communications referencing Medyc, data leaks, or requests for personal information. The company is implementing measures to protect its infrastructure and maintain service continuity, though users may experience temporary slowdowns or unavailability of certain modules.

Details emerging from one of Qbusoft's clients, the Drug Addiction and Psychiatric Treatment Center in Inowroclaw, shed more light on the technical aspects of the breach. Forensic analysis suggests that an unauthorized actor exploited a SQL injection vulnerability in the Medyc application interface around August 22-23. This exploit allowed for the exfiltration of an encrypted database archive, which was detected on September 8-9. The compromised data reportedly includes names, addresses, phone numbers, email addresses, and PESEL numbers – Poland's national identification number.

While the PESEL and name fields were encrypted in the database, the vendor indicated that the encryption method was weak, making decryption by attackers highly probable. Furthermore, the analysis revealed the execution of scripts targeting tables containing medical data, leading to the strong likelihood that attackers also obtained sensitive medical documentation and hospital treatment information cards. The treatment center emphasized the high risk this incident poses to the rights and freedoms of affected individuals.

Cybersecurity researchers from the Polish firm Zaufana Trzecia Strona have linked the Qbusoft attack to a threat actor known as "fingerprint," which also claimed responsibility for the earlier MyDr breach. This suggests a coordinated or ongoing campaign by the same group targeting Poland's healthcare sector.

In response to the escalating threats, Poland's Deputy Prime Minister and Minister of Digitization, Krzysztof Gawkowski, announced that the Central Bureau for Combating Cybercrime is investigating the Qbusoft incident as part of a broader inquiry into the MyDr attack. The country's cybersecurity incident response team for the electronic-health sector, CSiRT CeZ, in conjunction with the Ministry of Health, has also issued security recommendations for healthcare software providers, which were distributed on September 16. Gawkowski stressed that "absolute consequences will be drawn" for any private company found to have breached security procedures.

Both the Qbusoft and MyDr incidents are now under audit by Poland's Office for Personal Data Protection. The office has received over 50 complaints related to the MyDr breach alone and is inspecting the technical and organizational measures implemented by affected companies. The focus on the healthcare sector highlights its critical infrastructure status and the severe implications of data breaches involving sensitive patient information.

Synthesized by Vypr AI