A cyberattack on Polish healthcare software company Qbusoft has left patient records from its Medyc platform potentially in the hands of attackers, coming just weeks after a separate, larger breach hit another Polish medical software provider and rattled the country's entire health data infrastructure.
The attacker exploited an SQL injection vulnerability in Medyc's application interface during late August, according to a breach notification published last week by the Addiction and Psychiatric Treatment Center in Inowrocław, one of the healthcare facilities running the platform. SQL injection is one of the oldest and best-documented attack techniques in security research, allowing an attacker to manipulate a web application into pulling data directly from its database. Despite decades of awareness about the flaw, it remains a recurring entry point in healthcare system compromises.
Qbusoft confirmed on Friday that the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. In Poland, the national identification number, called a PESEL, functions similarly to a Social Security number in the United States and is a standard credential for identity verification across government services, banking and healthcare. Its theft puts affected patients at real risk of identity fraud.
The company said it had not confirmed the theft of clinical records. But the Inowrocław center told patients that Qbusoft found evidence the attacker ran scripts specifically targeting database tables containing medical information, making it "highly likely" that medical records were also pulled. The data in scope for that facility included hospital treatment records and discharge summaries from patients treated at its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026.
The intrusion occurred on August 22-23 and went undetected until the night of September 8-9, a gap of more than two weeks. By that point, the attacker had already transferred an encrypted archive of the database outside Qbusoft's systems. Some fields, including names and PESEL numbers, had been encrypted in the database. Qbusoft nonetheless advised the affected center to assume the attackers could decrypt that information without difficulty, given the specifics of how the protection was implemented.
Qbusoft patched the vulnerability on the day the breach was detected, restricted database access permissions, rotated passwords and technical credentials, and introduced additional monitoring. The company has not publicly commented on the incident through any official statement.
That silence drew a sharp response from Digital Affairs Minister Krzysztof Gawkowski, who said the Central Bureau for Combating Cybercrime had opened an investigation and criticized Qbusoft for failing to notify CERT Polska or the national incident response team for the healthcare sector before authorities reached out. "Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk," Gawkowski said. Poland's data protection authority separately announced that its president had ordered a formal audit of Qbusoft.
Medyc, which has operated as a cloud-based platform since 2014, is used across Polish medical practices and clinics for electronic medical records, patient scheduling, electronic prescriptions, referrals, sick notes, telemedicine and administrative billing. In a public notice, the company warned that its infrastructure had faced repeated attack attempts since the incident and that users might see temporary slowdowns or restricted access to certain modules.
The Same Attacker?
Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the alias "fingerprint" contacted the outlet claiming responsibility for the Medyc attack. The publication had previously linked that alias to the MyDr breach, a separate incident involving another Polish healthcare software vendor. Polish broadcaster RMF FM also reported that the same attackers behind MyDr were likely responsible for the Medyc intrusion, though Polish authorities have not formally attributed the attack to any individual or group.
The alleged attacker claimed to have obtained records on 5 million patients and 8 million private photographs, some of which Zaufana Trzecia Strona said may depict patients in sensitive medical settings. Neither figure has been independently confirmed, and the stolen data has not been made public. The actor reportedly framed the operations as an effort to expose weak security rather than profit from the data.
The MyDr breach, confirmed in August, potentially affected close to 19 million people across more than 12,000 healthcare facilities, involving over 2 terabytes of stolen data including names, PESEL numbers, prescription histories, diagnoses and appointment records. Poland has roughly 36.5 million residents, meaning the MyDr incident alone touched the records of nearly half the country's
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article:
