Qbusoft, a Polish provider of medical records and practice management software called Medyc, suffered a cyberattack in August. The breach occurred when an attacker exploited an SQL injection vulnerability in the platform's application interface.
The attackers obtained personal data including names, national identification numbers (PESEL), home addresses, phone numbers, and email addresses. While Qbusoft has not confirmed the theft of medical records, an affected healthcare provider stated that evidence suggests attackers executed scripts targeting database tables containing medical information, making it highly probable that some medical records were also stolen.
The Addiction and Psychiatric Treatment Center in Inowrocław reported that patients at its day treatment unit were affected, with potentially compromised medical information including hospital treatment records and discharge summaries. The affected records covered patients treated between July 2024 and August 2026.
The intrusion, which involved transferring an encrypted database archive outside Qbusoft's systems, was detected on September 9. Qbusoft fixed the SQL injection vulnerability on the day of discovery. The company also restricted database permissions, rotated passwords, and introduced additional monitoring to prevent future attacks.
Medyc has reported facing repeated attack attempts in recent weeks, leading to potential temporary unavailability of some services. Qbusoft has not yet issued a public statement regarding the investigation.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Qbusoft, a Polish medical software provider, experienced a data breach in August due to an SQL injection vulnerability in its Medyc platform. The attack exposed patient names, national identification numbers, addresses, phone numbers, and email addresses, with a high likelihood of medical records also being compromised.