< Back to all clusters
[TECHNOLOGY] · Poland · 12 sources

started · updated

Qbusoft Medyc software hit by massive cyberattack leaking patient data

A major cyberattack has targeted the Medyc software, produced by the Olsztyn-based company Qbusoft, potentially compromising the sensitive data of millions of Polish citizens. The breach, which occurred on August 22 and 23, 2026, was detected in early September.

While initial estimates suggested approximately one million patients were affected, hackers operating under the pseudonym ‘fingerprint’ claim to have stolen data for 5 million people and 8 million private photos. The stolen information may include names, PESEL numbers, addresses, phone numbers, email addresses, and sensitive medical documentation, such as hospital discharge summaries.

The attackers reportedly exploited a SQL injection vulnerability to access an encrypted database archive. Although some data was encrypted, experts warn that the encryption was weak and easily bypassable.

Minister of Digital Affairs Krzysztof Gawkowski confirmed the incident and stated that the Central Bureau for Combating Cybercrime is investigating. He also warned that strict consequences will follow if private companies are found to have violated security procedures. Notably, Qbusoft has not yet reported the incident to CERT Polska or the CSIRT CeZ team.

Entities

Central Bureau for Combating Cybercrime · Centralne Biuro Zwalczania Cyberprzestępczości · Inowrocław · Inowrocław Addiction Treatment and Psychiatric Center · Krzysztof Gawkowski · Medyc · Odwykowo-Psychiatryczny Ośrodek Leczniczy · Odwykowo-Psychiatryczny Ośrodek Leczniczy w Inowrocławiu · Personal Data Protection Office · Qbusoft · Qbusoft Sp. z o. o.

Claims

What the coverage asserts, and how many sources carry each claim.