# Polish medical data breaches

> Live situation record from CLSTR: https://clstr.news/situations/polish-medical-data-breaches
> Updated: 2026-09-24T16:14:48.000Z. Sources: 19. Developments: 2.

Poland has experienced significant cyberattacks targeting medical data systems. An initial breach at the MyDr medical system potentially compromised the personal and health information of 18.8 million people and affected over 12,000 medical facilities. The Ministry of Digital Affairs reported that the unauthorized access involved historical data up to April 2024, including names, PESEL numbers, and sensitive medical visit notes.

Subsequent reports identified a specific vulnerability in the Medyc software, developed by the Olsztyn-based company Qbusoft, which was exploited via a SQL injection. During a breach occurring between August 22 and August 23, 2026, attackers stole an encrypted database archive. One affected facility, the Addiction Treatment and Psychiatric Center in Inowrocław, reported that the compromised data could include names, PESEL numbers, addresses, phone numbers, email addresses, and sensitive medical documentation such as hospital discharge summaries.

Minister of Digital Affairs Krzysztof Gawkowski confirmed the incident and stated that the Central Bureau for Combating Cybercrime is conducting an investigation. Gawkowski noted that Qbusoft failed to report the incident to CERT Polska or the CSIRT CeZ team, promising ‘absolute consequences’ if security procedures were violated. While the stolen data was encrypted, experts warned the encryption was weak and easily bypassed. 

Newer developments regarding the Medyc software breach indicate a discrepancy in the scale of the impact. While initial estimates suggested approximately one million patients were affected, the attackers, using the pseudonym ‘fingerprint,’ claim to have stolen data for 5 million people and 8 million private photos.

## Claims

- The breach occurred on August 22 and 23, 2026. (disputed by 4 sources)
- The incident was detected on the night of September 8 and 9, 2026. (disputed by 4 sources)
- Qbusoft is the producer of the Medyc software. (corroborated by 10 sources)
- Minister of Digital Affairs Krzysztof Gawkowski promised strict consequences for private companies that violate security procedures. (corroborated by 7 sources)
- The attack utilized a SQL injection vulnerability in the Medyc software interface. (corroborated by 6 sources)
- The Central Bureau for Combating Cybercrime is investigating the incident. (corroborated by 5 sources)
- Qbusoft did not report the incident to CERT Polska or the CSIRT CeZ team. (corroborated by 4 sources)
- The breach at the Inowrocław center may include medical documentation such as hospital discharge summaries. (corroborated by 4 sources)

## Timeline

### 2026-09-24: Qbusoft Medyc software hit by massive cyberattack leaking patient data

A cyberattack on Qbusoft’s Medyc software has potentially leaked the medical and personal data of millions of Poles, including PESEL numbers and private photos, via a SQL injection vulnerability.

14 sources. https://clstr.news/cluster/qbusoft-medyc-software-breach-exposes-polish-patient-data

### 2026-08-31: Poland faces MyDr data breach and identity verification deadlines

A massive data breach at MyDr potentially affects 18.8 million people in Poland, while Ukrainian refugees face a deadline to confirm identities to maintain social benefits.

7 sources. https://clstr.news/cluster/poland-faces-mydr-data-breach-and-identity-verification-deadlines

---
Cite as: Polish medical data breaches. CLSTR, https://clstr.news/situations/polish-medical-data-breaches
