A Polish maker of medical software has confirmed that intruders took patient data through a flaw in its application interface, weeks after a separate breach in the country exposed records of nearly 19 million people.
Qbusoft sells Medyc, a platform clinics use for patient registration, records and prescriptions. Qbusoft went public on September 25. Its statement confirms that intruders reached personal data sitting on Medyc’s infrastructure and made off with it.
The confirmed haul includes names, PESEL national ID numbers, home addresses, phone numbers and email addresses. Qbusoft said theft of medical documentation is not yet confirmed; it logged dangerous attacks on September 9 and has reported them to Poland’s cybercrime bureau and data protection office.
A clinic that uses the platform filled in the mechanism. The Odwykowo-Psychiatryczny center in Inowroclaw told patients an intruder exploited an SQL injection flaw on August 22 and 23, then moved an encrypted database archive off the vendor’s systems. The export ran without a time limit, so every patient treated between July 2024 and August 2026 was likely included.
Qbusoft says repeated attacks have slowed the service and could limit some modules.
