Security1 publisher2 min readPublished
SQL injection in Qbusoft's Medyc software exposed Polish patients' PESEL numbers
Qbusoft confirmed an attacker stole patient data from its Medyc clinic software through an SQL injection flaw that went unnoticed for about 17 days. It is the second Polish clinic-software supplier to lose ID numbers in weeks, after MyDr lost data on nearly 19 million people in August.
The Watch · Security desk

What happened
- Medyc's export commands had no time limit, so the attacker took every patient treated at an Inowrocław addiction day unit from July 1, 2024 to August 23, 2026.
- Qbusoft confirmed that names, PESEL numbers, home addresses, phone numbers and email addresses were stolen, and has not said how many people were affected.
- Digital Affairs Minister Krzysztof Gawkowski wrote on X that Qbusoft had not notified CERT Polska or CSIRT CeZ, the e-Health Center's incident response team.
- Data protection chief Mirosław Wróblewski ordered an audit of the company, citing media reports that medical data on up to five million people may be involved.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Whoever holds the archive can approach addiction and psychiatric patients with their own treatment history in hand, and the clinic has warned patients about fake therapy offers built on exactly that.
- contradiction A Medyc clinic that scopes its patient notices from Qbusoft's public statement alone would leave out the discharge summaries the vendor privately called highly likely stolen.
- constraint Medyc clinics cannot count encryption at rest as a mitigation when deciding what to tell patients, because the vendor's own guidance is to treat names and PESEL numbers as plaintext.
- precedent Gawkowski's threat of the "strictest consequences" puts the choice of reporting channel on the enforcement table for Polish health-software vendors, alongside the breach itself.
According to a notice from the Odwykowo-Psychiatryczny Ośrodek Leczniczy in Inowrocław, Qbusoft's forensic findings trace the entry to an SQL injection flaw in Medyc's application interface [10]. It was exploited on August 22-23, 2026 [10]. The attacker packed the database into an encrypted archive and moved it off the vendor's systems [11]. Names and PESEL numbers were stored encrypted [13]. The vendor still told the clinic that, because of how the code was built, it should assume the data was easy to decrypt and that the attacker had it in plain text [13].
On medical records, the clinic's account goes further than the vendor's. The attacker ran scripts against tables holding medical data, and Qbusoft told the clinic it is highly likely that hospital discharge summaries were taken [14]. The clinic notified its patients on September 24 [9]. Qbusoft's own statement, posted on the Medyc website on September 25, said: "At this stage, the theft of medical documentation has not been confirmed" [3][5].
Detection came on the night of September 8 to 9 [11]. Counted from the August 22-23 exploitation, that is 16 to 18 days before anyone noticed [1]. Qbusoft says it removed the flaw the same day it found the attack, restricted database permissions, forced a rotation of all passwords and technical secrets, and put its infrastructure under constant monitoring [16]. The clinic's patients heard 15 days after detection [2]. Its systems have taken repeated attack attempts over the past week, the company says, and some modules may be limited or unavailable [7].
Qbusoft lists five bodies it did notify: the Central Cybercrime Bureau (CBZC), the data protection office UODO, CSIRT NASK, the e-Health Center and the Social Insurance Institution, ZUS [6]. Gawkowski's complaint is about the two incident-response teams missing from that list [18]. "In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced," he wrote [19].
MyDr, the August victim, is a Warsaw company whose software is used by about 12,000 healthcare facilities. Its leaked database held PESEL numbers, contact details, visit records, prescriptions and treatment history [2]. The published record does not say how MyDr was breached or whether one actor hit both vendors [2]. On what is public, the link between the two incidents is the kind of supplier and the kind of data: clinic-software vendors holding national ID numbers next to treatment records [1][2]. Gawkowski wrote that the CBZC is looking into the Qbusoft incident as part of a broader investigation [17].
What to watch
- A count of affected people from Qbusoft or from UODO's audit, set against the media reports of up to five million.
- Whether the CBZC's broader investigation attributes the Medyc and MyDr thefts to one actor or one method.
- Whether Qbusoft publicly confirms the discharge-summary theft, or other Medyc clinics issue notices matching the Inowrocław one.