SQL Injection Attack on Polish Medical Software Provider Exposes Patient Data
Qbusoft, developer of the Medyc medical records and practice management platform used in Poland, was breached in August after an attacker exploited an SQL injection vulnerability, a flaw that tricks a website into revealing database contents it should protect. The company confirmed that names, national identification numbers, home addresses, phone numbers and email addresses were stolen. While Qbusoft has not confirmed theft of medical records, one affected healthcare provider said it was told that attackers ran scripts against database tables containing medical information, making it likely that clinical data was also taken.
The Addiction and Psychiatric Treatment Center in Inowrocław confirmed that patients treated at its day unit between July 2024 and August 2026 may have had records exposed, including hospital treatment records and discharge summaries. Some identifying data such as names and national ID numbers had been encrypted, but Qbusoft warned the attackers could likely decrypt it. The intrusion was detected on September 9, and Qbusoft has since patched the vulnerability, restricted database permissions, rotated credentials, and added monitoring. Medyc says its systems have faced repeated attack attempts since, and some services may be intermittently unavailable.
This incident adds to a string of cyberattacks targeting Poland's healthcare sector in recent months, underscoring how attractive medical software providers are as targets due to the sensitive personal and clinical data they hold.