Skip to content

Security1 publisher2 min readPublished

Attacker pulled Polish patients' ID numbers from Medyc maker Qbusoft via SQL injection

Qbusoft's Medyc platform lost Polish patients' PESEL numbers and contact details to an SQL injection exploited in late August and caught on September 9. An addiction clinic says treatment records were likely taken too, and Poland's data regulator has ordered an audit of the supplier.

The Watch · Security desk

Illustration accompanying Attacker pulled Polish patients' ID numbers from Medyc maker Qbusoft via SQL injection

What happened

  • The Inowroclaw Addiction and Psychiatric Treatment Center says the stolen data covers patients of its addiction day-treatment unit from July 2024 through August 2026.
  • Names and PESEL numbers were encrypted in the database, but Qbusoft told the clinic to assume the attacker could decrypt them easily.
  • Qbusoft closed the injection flaw the day it was discovered, then restricted database permissions, rotated passwords and technical credentials, and added monitoring.
  • Digital Affairs Minister Krzysztof Gawkowski said the Central Bureau for Combating Cybercrime is investigating the Medyc attack as part of a broader inquiry.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Medyc customers have to decide on patient notices using their own evidence, as the Inowroclaw clinic did, because Qbusoft has not commented publicly on the investigation.
  • constraint If adopted, mandatory security certification and limits on how private companies process medical data would set new conditions for firms like Qbusoft that host Polish patient records.
  • precedent By faulting Qbusoft for not reporting first to CERT Polska and the health-sector response team, Gawkowski has told suppliers they are expected to report breaches themselves.

The clinic's account of the chain is short. According to the Inowroclaw center, an unauthorized person exploited an SQL injection vulnerability in Medyc's application interface in late August and moved an encrypted archive of a database outside Qbusoft's systems [6]. Detection came overnight on September 9 [7], at least nine days after the exploitation [1]. Qbusoft later found evidence that the attacker had run scripts against tables holding medical information [4]. At the clinic, the medical data potentially exposed includes hospital treatment records and discharge summaries [5].

What is confirmed depends on who is speaking. Medyc said Friday that the attackers took names, national ID numbers, home addresses, phone numbers and email addresses [2]. It said it had not confirmed that medical records were stolen [3]. The clinic goes further. It says Qbusoft's own findings make it "highly likely" that some medical records were taken [4].

The injection point and the exfiltration were both on the vendor side [6]. Medyc is a cloud platform that Polish providers use for medical records, registration, scheduling, diagnoses, e-prescriptions, sick notes, referrals and telemedicine [14]. The breach became public through a notice from one affected provider [1]. Neither the number of Medyc customers whose patients were in the archive nor the attacker's identity has been made public [1].

The earlier MyDr breach shows what one supplier can hold. Polish authorities say that incident, at a separate health-software company, potentially involved about 19 million people and approximately 12,000 healthcare organisations [23]. It came shortly before the Medyc intrusion [22]. Medyc says its infrastructure has faced repeated attack attempts in recent weeks [12]. "Due to the intensity and frequency of attacks, the website may periodically run slower and access to some modules may be temporarily limited or unavailable," the company said [13]. Gawkowski said Saturday that authorities had seen growing cybercriminal activity against healthcare organisations over the same weeks [20].

The minister has aimed at disclosure as much as at the flaw. "In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced," Gawkowski said [17]. "Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk," he said in a separate statement [18].

What to watch

  • Patient notices from other Medyc customers, which would give the first public count of affected providers.
  • Any finding by investigators that ties the Medyc and MyDr intrusions to the same actor.
  • The data protection authority's audit results and the draft text of the certification and data-processing rules.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories