started · updated
Qbusoft Medyc software hit by massive cyberattack leaking patient data
A major cyberattack has targeted the Medyc software, produced by the Olsztyn-based company Qbusoft, potentially compromising the sensitive data of millions of Polish citizens. The breach, which occurred on August 22 and 23, 2026, was detected in early September.
While initial estimates suggested approximately one million patients were affected, hackers operating under the pseudonym ‘fingerprint’ claim to have stolen data for 5 million people and 8 million private photos. The stolen information may include names, PESEL numbers, addresses, phone numbers, email addresses, and sensitive medical documentation, such as hospital discharge summaries.
The attackers reportedly exploited a SQL injection vulnerability to access an encrypted database archive. Although some data was encrypted, experts warn that the encryption was weak and easily bypassable.
Minister of Digital Affairs Krzysztof Gawkowski confirmed the incident and stated that the Central Bureau for Combating Cybercrime is investigating. He also warned that strict consequences will follow if private companies are found to have violated security procedures. Notably, Qbusoft has not yet reported the incident to CERT Polska or the CSIRT CeZ team.
Entities
Central Bureau for Combating Cybercrime · Centralne Biuro Zwalczania Cyberprzestępczości · Inowrocław · Inowrocław Addiction Treatment and Psychiatric Center · Krzysztof Gawkowski · Medyc · Odwykowo-Psychiatryczny Ośrodek Leczniczy · Odwykowo-Psychiatryczny Ośrodek Leczniczy w Inowrocławiu · Personal Data Protection Office · Qbusoft · Qbusoft Sp. z o. o.
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The attackers claim to possess data for 5 million people and 8 million medical images. biznes.wprost.pl
- [● 4 SOURCES] Qbusoft did not report the incident to CERT Polska or the CSIRT CeZ team. biznes.wprost.pl · next.gazeta.pl · www.rmf24.pl · wiadomosci.onet.pl
- [● 5 SOURCES] The attackers utilized a SQL injection vulnerability to access the database. biznes.wprost.pl · www.dobreprogramy.pl · ino.online · warszawawpigulce.pl
- [● 5 SOURCES] The Minister of Digital Affairs announced that strict consequences will follow if a private company violated security procedures. biznes.wprost.pl · www.fakt.pl · next.gazeta.pl · www.rmf24.pl · wiadomosci.onet.pl
- [● 2 SOURCES] The data breach may affect over one million patients across hundreds of facilities. biznes.wprost.pl · warszawawpigulce.pl
- [● 4 SOURCES] The Central Bureau for Combating Cybercrime is conducting an investigation into the incident. biznes.wprost.pl · www.fakt.pl · warszawawpigulce.pl · wiadomosci.onet.pl
- [● 10 SOURCES] Qbusoft is the producer of the Medyc software. biznes.wprost.pl · www.dobreprogramy.pl · www.fakt.pl · ino.online · next.gazeta.pl · +4 more
- [● 4 SOURCES] The breach at the Inowrocław center may include medical documentation such as hospital discharge summaries. biznes.wprost.pl · www.dobreprogramy.pl · ino.online · warszawawpigulce.pl
- [DISPUTED] The breach occurred on August 22 and 23, 2026. biznes.wprost.pl · www.dobreprogramy.pl · ino.online · www.rmf24.pl
- [● 5 SOURCES] The Central Bureau for Combating Cybercrime is investigating the incident. biznes.wprost.pl · www.fakt.pl · next.gazeta.pl · wiadomosci.onet.pl · warszawawpigulce.pl
- [● 6 SOURCES] The attack utilized a SQL injection vulnerability in the Medyc software interface. biznes.wprost.pl · www.dobreprogramy.pl · ino.online · www.rmf24.pl · warszawawpigulce.pl
- [DISPUTED] The incident was detected on the night of September 8 and 9, 2026. biznes.wprost.pl · www.dobreprogramy.pl · ino.online · www.rmf24.pl