← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Polish medical software provider Qbusoft suffers data breach via SQL injection

🔄 Updated 3d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Qbusoft's Medyc platform breached via SQL injection in August.
  • Personal data including names, PESEL numbers, addresses, and contacts stolen.
  • Medical records likely compromised, affecting patients at a treatment center.
  • Vulnerability fixed; Qbusoft implemented additional security measures.

Data Breach at Qbusoft

Qbusoft, a Polish provider of medical records and practice management software called Medyc, suffered a cyberattack in August. The breach occurred when an attacker exploited an SQL injection vulnerability in the platform's application interface.

Compromised Patient Information

The attackers obtained personal data including names, national identification numbers (PESEL), home addresses, phone numbers, and email addresses. While Qbusoft has not confirmed the theft of medical records, an affected healthcare provider stated that evidence suggests attackers executed scripts targeting database tables containing medical information, making it highly probable that some medical records were also stolen.

The Addiction and Psychiatric Treatment Center in Inowrocław reported that patients at its day treatment unit were affected, with potentially compromised medical information including hospital treatment records and discharge summaries. The affected records covered patients treated between July 2024 and August 2026.

Vulnerability and Remediation

The intrusion, which involved transferring an encrypted database archive outside Qbusoft's systems, was detected on September 9. Qbusoft fixed the SQL injection vulnerability on the day of discovery. The company also restricted database permissions, rotated passwords, and introduced additional monitoring to prevent future attacks.

Ongoing Security Concerns

Medyc has reported facing repeated attack attempts in recent weeks, leading to potential temporary unavailability of some services. Qbusoft has not yet issued a public statement regarding the investigation.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Qbusoft, a Polish medical software provider, experienced a data breach in August due to an SQL injection vulnerability in its Medyc platform. The attack exposed patient names, national identification numbers, addresses, phone numbers, and email addresses, with a high likelihood of medical records also being compromised.