Polish Healthcare Software Provider Qbusoft Breached via SQL Injection, Patient Data at Risk
A recent cyberattack on **Qbusoft**, a Polish healthcare software provider, has exposed personal data of patients, including potentially sensitive medical records. The breach, attributed to an SQL injection vulnerability, highlights a concerning trend of increasing cybercriminal activity targeting Poland's healthcare sector.
Hackers have successfully exfiltrated personal data from **Qbusoft**, the developer behind the **Medyc** medical records and practice management platform. The incident, which exploited an SQL injection vulnerability in August, is the latest in a series of attacks on Poland's medical infrastructure.
An SQL injection flaw allows attackers to manipulate a website's database queries, granting unauthorized access to stored information. In this case, **Medyc** confirmed that attackers obtained names, national identification numbers, home addresses, phone numbers, and email addresses.
While **Qbusoft** has not definitively confirmed the theft of medical records, an affected healthcare provider, the **Addiction and Psychiatric Treatment Center in InowrocΕaw**, reported being informed that **Qbusoft** found evidence of scripts targeting medical information database tables, making the compromise of such records "highly likely."
The **InowrocΕaw** center specified that patients treated by its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026 were affected, with potentially compromised medical information including hospital treatment records and discharge summaries. Although some identifying data like names and national identification (**PESEL**) numbers were encrypted, **Qbusoft** advised assuming attackers could easily decrypt them.
**Qbusoft** addressed the SQL injection vulnerability on the day of discovery, implementing restricted database permissions, rotating credentials, and enhancing monitoring. The company has not yet issued a public statement on the ongoing investigation.
**Medyc** has acknowledged facing repeated attack attempts and warned of potential service disruptions. "Due to the intensity and frequency of attacks, the website may periodically run slower and access to some modules may be temporarily limited or unavailable," the company stated.
### Official Response and Broader Concerns
**Krzysztof Gawkowski**, Poland's Digital Affairs Minister, confirmed that the **Central Bureau for Combating Cybercrime** is investigating the **Medyc** attack as part of a wider inquiry. He criticized **Qbusoft** for not initially reporting the incident to **CERT Polska**, the national incident response team for the healthcare sector.
"In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced," Gawkowski warned, emphasizing that "hiding attacks by companies is the biggest mistake, as it always puts citizens at risk."
Poland's data protection authority has since ordered an audit of the company behind **Medyc**. Gawkowski also revealed that Polish authorities are observing escalating cybercriminal activity against healthcare organizations and are preparing new regulations to bolster medical information protection, including mandatory security certifications and restrictions on how private companies process medical data.
### Echoes of Previous Breaches
The **Medyc** intrusion follows closely on the heels of another significant breach involving **MyDr**, another Polish healthcare software company. The **MyDr** incident potentially impacted information related to approximately 19 million people and 12,000 healthcare organizations.
Interestingly, the **InowrocΕaw** treatment center affected by the **Medyc** incident was also among those impacted by the **MyDr** breach. Polish cybersecurity publication **Zaufana Trzecia Strona** reported that a group known as "fingerprint," previously linked to the **MyDr** breach, claimed responsibility for the **Medyc** intrusion, asserting they obtained records for 5 million patients and 8 million private photographs. The group allegedly stated their motive was to expose weak cybersecurity rather than financial gain, though these claims remain unverified by authorities.
Polish authorities have not publicly attributed the **Medyc** breach to any specific individual or group, and the stolen information has not yet been publicly released.