Security1 publisher2 min readPublished
Poland's MyDr attacker breached a second clinic-software vendor, Zaufana Trzecia Strona reports
Fingerprint, who took data on over 18 million Poles from MyDr, stole Qbusoft's Medyc.pl patient database by SQL injection, Zaufana Trzecia Strona reports. Qbusoft is the second Polish medical-practice software vendor the actor has breached, and one Inowrocław clinic has had patient data taken in both leaks.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The Inowrocław centre's notice says the intrusion at Qbusoft ran on August 22 and 23, and the company learned of it on the night of September 8 to 9.
- The stolen database held names, PESEL numbers, home addresses, phone numbers and email addresses, and the vendor says the encryption on names and PESEL numbers was easy to break.
- On August 29, fingerprint said in its most recent public message that information about another incident would appear soon.
- The notice puts a high chance on the attackers having also taken medical data in the form of discharge summaries.
- Qbusoft had not answered questions Zaufana Trzecia Strona sent on September 22 by the time the outlet published.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Because the encryption was weak, each Medyc record taken gives the attacker a readable name, PESEL number and contact details, possibly with a discharge summary attached.
- precedent Fingerprint announced this breach 10 days before Qbusoft detected it. On this record, the actor's own posts warned Polish practice-software vendors sooner than their own monitoring did.
- constraint Until Qbusoft gives a count, patients and clinics can size the breach only from visit numbers, an estimate Zaufana Trzecia Strona puts above one million people.
Fingerprint went public six days after the intrusion ended [2]. Qbusoft found out 16 days after the intrusion and 10 days after the actor's post [3][4].
The clinic's notice names SQL injection as the way in. It says the attackers took a database archive described as encrypted [4]. The encrypted fields it lists are first name, surname and PESEL number. The vendor's own assessment is that the encryption was easy to break, so the attackers could read the data [6].
The public record is a notice from an addiction and psychiatric treatment centre in Inowrocław, first reported by CyberDefence24 [3]. It supplies the dates, the method and the field list [4][5][6]. The link to fingerprint comes from Zaufana Trzecia Strona. The outlet says it knew of the incident before the notice, put questions to Qbusoft on September 22, and can confirm a large-scale leak by the actor behind MyDr [1][2][9].
Patient numbers are an estimate. Medyc's website claims more than 10,000 visits a day [10]. MyDr claimed ten times that and held data on more than 18 million patients [11]. The same ratio would put Medyc near 1.8 million people [1]. Zaufana Trzecia Strona puts the figure at more than a million and says it is guessing because the company has not answered [12].
On the outlet's attribution, one actor has now taken patient data from two vendors of Polish medical-practice software. It announced the second incident in public before the vendor knew of it [2][8][4]. Two targets in one narrow software category amount to repeat selection. Zaufana Trzecia Strona's report does not describe how MyDr was breached or what fingerprint wants, so it cannot show whether one technique was reused across vendors [2].
For the Inowrocław centre's patients, the notice puts a high chance on discharge summaries being among the stolen data [7]. Zaufana Trzecia Strona's advice is to block PESEL numbers. The outlet says it has no other [13].
What to watch
- Qbusoft's reply to Zaufana Trzecia Strona's September 22 questions, and any patient count it gives.
- Breach notices from other clinics that run Medyc. Each would add a real count to set against the visit-based estimate.
- A new fingerprint post trailing or naming a third Polish medical-software vendor.