Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider

Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Hackers stole patient data from Qbusoft’s Medyc platform after exploiting an SQL injection flaw, exposing personal and possibly medical records from clinics in Poland. The incident follows a separate breach at MyDr that exposed records of nearly 19 million people, prompting government scrutiny and an audit by Poland’s data protection authority. #Qbusoft #Medyc #MyDr #CBZC #UODO #CSIRTNASK #CERTPolska #CSIRTCeZ

Keypoints

  • Hackers breached Qbusoft’s Medyc platform and stole patient data.
  • The attack exploited an SQL injection vulnerability in the application interface.
  • Stolen data included names, PESEL numbers, addresses, phone numbers, and email addresses.
  • The attacker may also have accessed medical records and discharge summaries.
  • Polish authorities, including CBZC and UODO, are investigating the incident.

Read More: https://www.helpnetsecurity.com/2026/09/29/qbusoft-medyc-data-breach-poland/