Cyber & AI intelligence
Wasteland.
Briefs indexed2912
Issues30
Published Mondays07:30 CT
▣ Breach MEDYC-POLAND-HEALT 2026-09-28

Medyc: SQL Injection Exposes Polish Patient Data

"An attacker used an SQL injection flaw to steal a database archive from Qbusoft, the company in Olsztyn that makes Medyc, a medical records and practice management platform used by hundreds of Polish healthcare…"

An attacker used an SQL injection flaw to steal a database archive from Qbusoft, the company in Olsztyn that makes Medyc, a medical records and practice management platform used by hundreds of Polish healthcare facilities. Medyc said on Friday, September 25, that names, PESEL national identification numbers, home addresses, phone numbers and email addresses were taken. The company has not confirmed that medical records were stolen. However, at least one affected provider says Qbusoft told it this was "highly likely." Nobody has confirmed how many people are affected. Zaufana Trzecia Strona estimated at least 1 million. The attackers claim 5 million patients and 8 million "very private" photos, and no authority has verified those figures. This is the latest in a run of attacks on Poland's healthcare sector that also includes MyDr and Zdrowit.

What Happened

Most of the technical detail comes from breach notices sent by healthcare providers that use Medyc. The first to become public came from the Addiction and Psychiatric Treatment Center in Inowrocław (Terapia Inowrocław). Its notice has been quoted by The Record, Sekurak, wPolsce24 and StartupKit. According to the center:

A second Medyc customer, Centrum eZdrowia Sp. z o.o., has also notified patients, Sekurak reports. It is a private company, not the government's CeZ. It says it serves more than 500,000 patients but has not said how many were affected.

On September 24, Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski confirmed that the Central Cybercrime Bureau (CBZC) is investigating the incident as part of a wider investigation. According to Zaufana Trzecia Strona, Gawkowski said Qbusoft reported the attack to CBZC but not to CSIRT CEZ (the health-sector incident response team) or to CERT Polska. Poland Insight reports that UODO has announced an inspection of Qbusoft.

Attribution: CyberDefence24 and Zaufana Trzecia Strona, as cited by Poland Daily 24 and wPolsce24, attribute the breach to the actor known as "fingerprint," the same actor blamed for the recent MyDr leak. Zaufana Trzecia Strona says a group using that name contacted it after its first article. No authority has confirmed the link, so treat it as reported, not established.

What Was Taken

Confirmed by Medyc and affected providers: first names, surnames, PESEL numbers, home or temporary addresses, phone numbers and email addresses.

Very likely: medical records. Qbusoft found that the attacker ran scripts against database tables holding medical data. The Inowrocław center says the records likely exposed include hospital treatment records and discharge summaries (karta informacyjna leczenia szpitalnego). That center treats addiction and psychiatric patients, so the data is especially sensitive.

Encryption did not protect the data. Names and PESEL numbers were encrypted in the database. But because of how the code was built, Qbusoft told its customers to assume the attacker could easily decrypt them and now holds them in plain text.

Time span: For the Inowrocław day treatment unit, the stolen records cover July 1, 2024 to August 23, 2026. Qbusoft told the center that the export commands had no date limit. A separate source quoted by Zaufana Trzecia Strona says the attacker took the whole database, going back to when the company started, up to seven years.

Scale: accounts differ. - Zaufana Trzecia Strona: at least 1 million people, a figure it calls conservative. - The attackers ("fingerprint"): 5 million patients plus 8 million photos. Zaufana Trzecia Strona says the photos may show patients undressed but could not confirm the number. - Background figures: Medyc handled more than 10,000 appointments a day for hundreds of facilities (Poland Daily 24, wPolsce24). One affected provider alone reports more than 500,000 patients (Sekurak). - Neither UODO nor law enforcement has confirmed any total (Alert Medyczny, Poland Insight).

Why It Matters

One vendor breach reaches hundreds of clinics. Many small practices share a single SaaS vendor, so one flaw at that vendor exposes all of them at once. Each clinic is still the data controller legally, but it has almost no view into how the vendor secures its systems.

Stolen datasets can be combined. StartupKit notes that at least one clinic has told patients it was affected by both the MyDr and Medyc breaches. If one actor is behind both, as reported, it could merge the two datasets into much richer profiles. PESEL numbers plus contact details plus psychiatric or addiction treatment history is ideal material for extortion, targeted phishing and identity fraud. A national ID number cannot easily be replaced, and a medical history cannot be replaced at all.

Delays in reporting slow the response. According to the minister's account, the national health and CERT teams were not notified, even though their help is free. It also took about two weeks from detection to the first public notice. Both widen the window for criminals to use the data before patients are warned.

The encryption offered no real protection. Field-level encryption that the vendor itself calls "easy to decrypt" suggests the keys were stored with, or could be derived from, the application the attacker had compromised.

The Attack Technique

The attacker got in through SQL injection in an API endpoint of the Medyc application. This is a well-known class of bug that is easy to prevent. Based on the provider notices, the attack went like this:

  1. Initial access: injected SQL through an exposed Medyc API endpoint (August 22–23).
  2. Collection: ran scripts against patient identity tables and medical data tables. The queries had no date limit, so entire tables were pulled.
  3. Staging: packaged the data into an encrypted archive.
  4. Exfiltration: moved the archive outside Qbusoft's infrastructure. Zaufana Trzecia Strona reports that, as with MyDr, Medyc's main systems were hosted in the cloud.
  5. Detection: about 17 days later (September 8–9).
  6. Monetization or pressure: public claims about the scale of the theft sent to the press, in the style of an extortion group.

The permissions Qbusoft restricted after the attack suggest the database account behind the API could read far more data than it needed. That is what turned a single injection point into a full database dump.

What Organizations Should Do

  1. Eliminate SQL injection at the source. Use parameterized queries or ORM bindings everywhere, including internal and partner-facing API endpoints. Add SAST/DAST scans and a WAF with SQLi rules as backup layers, not as the only fix.
  2. Enforce least privilege on the database. Service accounts behind APIs should reach only the tables and rows they need. Reads of clinical tables should require separate credentials and be logged.
  3. Detect bulk exports and unusual queries. Alert on unbounded SELECTs, full-table reads, dump or archive creation, and large outbound transfers from database hosts. A 17-day gap between attack and detection is too long.
  4. Encrypt properly or don't claim it. Keep field-level encryption keys in a KMS or HSM separate from the application layer, so a compromised app cannot decrypt every record.
  5. Healthcare providers: audit your SaaS vendors now. Ask Medyc and similar vendors for evidence of penetration tests, how they handle vulnerability reports, what their breach notification timelines are, and what their data processing agreements say. Find out which of your patients are in which vendor systems, so you can tell quickly who is affected by a combined MyDr/Medyc exposure.
  6. Report early and to the right teams. In Poland, notify CSIRT CEZ and CERT Polska alongside CBZC and UODO. Tell affected patients about the risk of PESEL fraud and point them to the PESEL reservation service (zastrzeżenie PESEL) and phishing warnings.

Sources: Cyberattack on Polish medical software provider exposes ... | Sprawcy ataku na system Medyc twierdzą, że ukradli dane 5 milionów... | Cyberatak na system Medyc. Sprawcy twierdzą, że mają dane 5 mln osó... | Polish Healthcare Cyberattacks: MyDr, Medyc and Zdrowit | Kolejny wyciek danych medycznych Polaków. Chodzi o oprogramowanie M... | Healthcare Bug Bounties Should Start Before a Breach StartupKit | Another major data breach in Poland. Same attacker suspected | Służby w akcji po katastrofalnym wycieku. Cyberatak na system Medyc...