Breaches · 6h ago
Qbusoft’s Medyc medical records and practice-management platform was breached in August after an attacker exploited an SQL injection flaw, and affected providers say patient personal data was taken. Medyc said the stolen data included names, national identification numbers, home addresses, phone numbers and email addresses.
The attack worked by feeding crafted input into Medyc’s web application interface and turning that path into database access. One provider said Qbusoft found evidence of scripts aimed at tables containing medical information, and Qbusoft told it to assume encrypted identifiers could be decrypted, so “encrypted in the database” did not mean safe here.
For clinics using Medyc, the exposure is not limited to a website incident: identity data can be enough for fraud even if clinical notes were never taken. What remains unsettled is how much medical record content left the system, but the patient-data breach already sits inside the trusted workflow that stores and serves it.
2 sources covering this story
A data breach at Qbusoft's Medyc platform exposed the names, PESEL numbers and contact details of Polish patients.
The Record from Recorded Future
Cyberattack on Polish medical software provider exposes patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.
Part of the PlainSec briefing for 2026-09-29