Polish Medical Software Provider Medyc Breached via SQL Injection, Exposing Patient Data
Hackers exploited an SQL injection vulnerability in the Medyc platform, a Polish healthcare software provider, leading to the theft of patient names, national identification numbers, and potentially medical records.

Hackers have successfully breached Medyc, a prominent Polish healthcare software provider, exfiltrating sensitive personal data from its systems. The attack, which exploited a critical SQL injection vulnerability, has raised significant concerns within Poland's medical sector, which has been a target for cybercriminals in recent months.
Qbusoft, the developer behind the Medyc medical records and practice management platform, confirmed that the attackers gained access in August. The vulnerability, identified as an SQL injection flaw, allowed unauthorized individuals to trick the application into granting access to its underlying database. This type of attack is notorious for its ability to expose vast amounts of stored information.
The stolen data includes patient names, national identification numbers (PESEL), home addresses, phone numbers, and email addresses. While Medyc initially stated it had not confirmed the theft of actual medical records, one affected healthcare provider reported that Qbusoft found evidence of scripts targeting database tables containing medical information, making the exfiltration of such data "highly likely."
The Addiction and Psychiatric Treatment Center in Inowrocław was among the affected entities. Patients treated at its day treatment unit between July 2024 and August 2026 may have had their hospital treatment records and discharge summaries compromised. Although some identifying information was encrypted, Qbusoft advised the center to assume the attackers could decrypt it.
Qbusoft claims to have patched the SQL injection vulnerability on September 9, the same day the intrusion was detected. The company also implemented additional security measures, including restricting database permissions, rotating credentials, and enhancing monitoring. Despite these efforts, Medyc has warned users of potential service disruptions due to the intensity and frequency of ongoing attack attempts.
Poland's Digital Affairs Minister, Krzysztof Gawkowski, confirmed that the Central Bureau of Cybercrime is investigating the Medyc incident as part of a broader inquiry into cyberattacks targeting the healthcare sector. He also criticized Qbusoft for not promptly reporting the breach to CERT Polska, emphasizing the severe consequences for companies that conceal cyber incidents.
This breach follows closely on the heels of another significant cyberattack on MyDr, another Polish healthcare software company, which potentially impacted approximately 19 million individuals and 12,000 healthcare organizations. Both incidents highlight a growing trend of cybercriminal activity targeting sensitive medical data in Poland.
Authorities are reportedly preparing new regulations to bolster protections for medical information, including mandatory security certifications and stricter data processing rules for private companies. The investigation into the Medyc breach is ongoing, with Polish authorities yet to publicly attribute the attack to a specific threat actor.