Cyberattack on Polish medical software provider exposed patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to 2026-9-28 14:1:7 Author: therecord.media(查看原文) 阅读量:0 收藏

Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.

Qbusoft, which develops the Medyc medical records and practice management platform, was breached after an attacker exploited an SQL injection vulnerability in August, according to a notification issued last week by one of the healthcare providers affected by the incident.

SQL injection is a security flaw that allows hackers to trick a website into giving them access to information stored in its database.

Medyc said Friday the attackers obtained names, national identification numbers, home addresses, phone numbers and email addresses. The company said it had not confirmed the theft of medical records, but an affected healthcare provider said it was informed that Qbusoft had found evidence the attackers executed scripts targeting database tables containing medical information, making it “highly likely” that they also obtained some medical records.

The Addiction and Psychiatric Treatment Center in the central city of Inowrocław said patients at its day treatment unit were affected and that potentially compromised medical information included hospital treatment records and discharge summaries.

According to the center, an unauthorized person exploited an SQL injection vulnerability in Medyc’s application interface in late August and transferred an encrypted archive of a database outside Qbusoft’s systems. The intrusion was detected overnight on September 9.

The center said the affected records covered patients treated by its Day Treatment Unit for Addiction Treatment between July 2024 and August 2026.

Some identifying information, including names and national identification — or PESEL — numbers, had been encrypted in the database, the center said. However, Qbusoft advised the healthcare provider to assume the attackers could easily decrypt the information.

Qbusoft fixed the SQL injection vulnerability on the day the attack was discovered, according to the center. The company also restricted database permissions, rotated passwords and other technical credentials, and introduced additional monitoring. Qbusoft has not publicly commented on the investigation.

Medyc said its infrastructure has faced repeated attack attempts in recent weeks and warned that some services could be temporarily unavailable.

“Due to the intensity and frequency of attacks, the website may periodically run slower and access to some modules may be temporarily limited or unavailable,” the company said. “We are taking steps to protect our infrastructure and ensure the continuity of our services.”

Medyc is a cloud-based platform used by Polish healthcare providers for electronic medical records, patient registration and scheduling, diagnoses, electronic prescriptions, sick notes and referrals, telemedicine, and administrative services.

Investigation continues

Digital Affairs Minister Krzysztof Gawkowski said Thursday that the Central Bureau for Combating Cybercrime was investigating the Medyc attack as part of a broader inquiry.

He also criticized Qbusoft for not initially reporting the incident to CERT Polska or the national incident response team responsible for the healthcare sector.

“In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced,” Gawkowski said.

“Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk,” he added in a separate statement.

Poland’s data protection authority said Friday that its president had ordered an audit of the company behind Medyc.

Gawkowski said Saturday that Polish authorities had observed growing cybercriminal activity targeting healthcare organizations in recent weeks and were preparing regulations to strengthen protections for medical information.

The proposals include mandatory security certification and restrictions on how private companies can process medical data, according to the minister.

Healthcare attacks

The Medyc intrusion came shortly after another major breach involving MyDr, a separate Polish healthcare software company.

Polish authorities have said the MyDr incident potentially involved information relating to about 19 million people and approximately 12,000 healthcare organizations.

MyDr develops software used by healthcare providers to manage medical practices and electronic records and connects providers to Poland’s nationwide electronic health platform, which supports services including electronic prescriptions and referrals.

MyDr said it identified and removed the cause of the incident and introduced additional safeguards but has not publicly detailed the vulnerability used by the attackers.

The Inowrocław treatment center affected by the Medyc incident was also among the organizations affected by the MyDr breach.

Polish cybersecurity publication Zaufana Trzecia Strona reported that a person or group using the name “fingerprint,” which the publication previously linked to the MyDr breach, contacted it claiming responsibility for the Medyc intrusion.

The purported attackers claimed to have obtained records concerning 5 million patients and 8 million private photographs. Zaufana Trzecia Strona said it could not independently verify those figures.

The actor reportedly claimed that the operation was intended to expose weak cybersecurity rather than achieve financial gain. Polish broadcaster RMF FM separately reported that attackers connected to the MyDr breach were likely behind the Medyc breach.

Polish authorities have not publicly attributed the Medyc breach to a particular individual or group, and the stolen information has not been publicly released.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/poland-cyberattack-medical-medyc
如有侵权请联系:admin#unsafe.sh