< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [INTERNATIONAL]

2 clusters · 18 sources · 25 days · First seen · Last updated

Polish medical data breaches

Overview

Poland has experienced significant cyberattacks targeting medical data systems. An initial breach at the MyDr medical system potentially compromised the personal and health information of 18.8 million people and affected over 12,000 medical facilities. The Ministry of Digital Affairs reported that the unauthorized access involved historical data up to April 2024, including names, PESEL numbers, and sensitive medical visit notes.

Subsequent reports identified a specific vulnerability in the Medyc software, developed by the Olsztyn-based company Qbusoft, which was exploited via a SQL injection. During a breach occurring between August 22 and August 23, 2026, attackers stole an encrypted database archive. One affected facility, the Addiction Treatment and Psychiatric Center in Inowrocław, reported that the compromised data could include names, PESEL numbers, addresses, phone numbers, email addresses, and sensitive medical documentation such as hospital discharge summaries.

Minister of Digital Affairs Krzysztof Gawkowski confirmed the incident and stated that the Central Bureau for Combating Cybercrime is conducting an investigation. Gawkowski noted that Qbusoft failed to report the incident to CERT Polska or the CSIRT CeZ team, promising ‘absolute consequences’ if security procedures were violated. While the stolen data was encrypted, experts warned the encryption was weak and easily bypassed.

Newer developments regarding the Medyc software breach indicate a discrepancy in the scale of the impact. While initial estimates suggested approximately one million patients were affected, the attackers, using the pseudonym ‘fingerprint,’ claim to have stolen data for 5 million people and 8 million private photos.

Entities

Central Bureau for Combating Cybercrime · Odwykowo-Psychiatryczny Ośrodek Leczniczy · Inowrocław · Qbusoft Sp. z o. o. · Medyc

Claims

What the coverage asserts, and how many sources carry each claim.

Coverage disagrees

Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 13 sources
    Qbusoft Medyc software hit by massive cyberattack leaking patient data

    A cyberattack on Qbusoft’s Medyc software has potentially leaked the medical and personal data of millions of Poles, including PESEL numbers and private photos, via a SQL injection vulnerability.

  2. 26 days ago

    [INTERNATIONAL] 7 sources
    Poland faces MyDr data breach and identity verification deadlines

    A massive data breach at MyDr potentially affects 18.8 million people in Poland, while Ukrainian refugees face a deadline to confirm identities to maintain social benefits.

Sources

crn.pl · dlaszpitali.pl · dobreprogramy.pl · dzienniknarodowy.pl · fakt.pl · ino.online · medonet.pl · morningstar.be · newsroom.salon24.pl · next.gazeta.pl · niezalezna.pl · polityka.co.pl · rmf24.pl · rynekzdrowia.pl · spidersweb.pl · warszawawpigulce.pl · wiadomosci.onet.pl · wykop.pl

This summary has been updated 2 times: see revision history