Polish healthcare software provider Qbusoft suffered a breach of its Medyc cloud platform after an attacker exploited an SQL-injection vulnerability in late August. The intruder exfiltrated an encrypted database archive containing personal data and may have accessed medical records, including records belonging to patients of Inowrocław’s Addiction and Psychiatric Treatment Center. Qbusoft detected the intrusion on September 9 and remediated the flaw.
Polish cybercrime, data-protection, and government authorities opened investigations, while criticizing Qbusoft’s initial failure to notify national incident-response bodies. An actor calling itself “fingerprint” claimed responsibility and alleged theft of data on 5 million patients and 8 million private photographs, but those claims are unverified and authorities have not publicly attributed the attack. The incident follows a separate recent breach of Poland’s MyDr medical system that reportedly exposed personal information for nearly 19,000 people.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Qbusoft detected the Medyc intrusion overnight and fixed the exploited SQL injection vulnerability that day. It also restricted database permissions, rotated credentials, and added monitoring.
An unauthorized person exploited an SQL injection vulnerability in Qbusoft's Medyc application interface and exfiltrated an encrypted database archive. The platform is used by Polish healthcare providers for medical-records and practice-management functions.
A purported actor calling itself “fingerprint” contacted Zaufana Trzecia Strona and claimed responsibility, alleging theft of records for 5 million patients and 8 million private photographs. The claims were not independently verified, and Polish authorities made no public attribution.
Poland's Central Bureau for Combating Cybercrime began investigating the Medyc attack, the data-protection authority ordered an audit of the company behind Medyc, and the Digital Affairs Minister criticized Qbusoft for not initially reporting the incident to national response bodies.
The Addiction and Psychiatric Treatment Center in Inowrocław said attackers had run scripts targeting database tables containing medical information, making theft of medical records highly likely. Its affected Day Treatment Unit for Addiction Treatment held records for patients treated from July 2024 through August 2026.
A separate breach at Polish healthcare software provider MyDr preceded the Medyc incident. Authorities said it could involve data concerning approximately 19 million people and 12,000 healthcare organizations, while another report described exposure of personal information of nearly 19,000 people.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcemalware.news
Open sourcemedyc.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.