The confirmed data extracted includes patients’ full names, national identification numbers (PESEL), residential or temporary addresses, telephone numbers, and email addresses. While Qbusoft stated on September 28 that the theft of medical records has not been definitively confirmed, forensic analysis conducted by an affected healthcare provider suggests a high likelihood that sensitive health data was compromised. The provider, the Addiction and Psychiatric Treatment Center in Inowrocław, noted that scripts were executed targeting database tables containing medical information, including hospital treatment records and discharge summaries. The affected records cover patients treated by the center’s Day Treatment Unit between July 2024 and August 2026.
The breach highlights significant vulnerabilities in the encryption implementation used by the platform. Although certain fields, including names and PESEL numbers, were encrypted in the database, Qbusoft advised the affected provider to assume the attackers could easily decrypt the information. This assessment is based on the specific way the encryption was deployed, effectively rendering the protection insufficient against a determined attacker with database access.
In response to the discovery, Qbusoft fixed the SQL injection vulnerability on the day the attack was identified. The company also restricted database permissions, rotated passwords and other technical credentials, and introduced additional monitoring measures. Medyc has warned that its infrastructure has faced repeated attack attempts in recent weeks, potentially leading to temporary service unavailability or reduced performance for users relying on the platform for patient registration, electronic prescriptions, and telemedicine.
Digital Affairs Minister Krzysztof Gawkowski announced that the Central Bureau for Combating Cybercrime is investigating the incident as part of a broader inquiry into threats against Poland’s digital infrastructure. Gawkowski criticized Qbusoft for failing to initially report the incident to CERT Polska or the national incident response team responsible for the healthcare sector. “In the event of a breach of any security procedure by a private company, the strictest consequences will be enforced,” the minister stated. The government has subsequently issued new security recommendations to companies supplying software to the healthcare sector.
This breach follows a separate major incident in August involving MyDr, a system used by approximately 12,000 healthcare providers, where data belonging to nearly 19 million people was exposed, including information on medicines and prescriptions. The sequential nature of these attacks has intensified scrutiny on the security resilience of Poland’s medical software ecosystem. Meanwhile, Polish Foreign Minister Radoslaw Sikorski has warned that Russia may be preparing a major operation and could stage a false-flag attack to justify further mobilization, adding a geopolitical dimension to the ongoing security concerns within the region.
Qbusoft has not provided further public commentary on the ongoing investigation. The distinction between confirmed personal data theft and the suspected compromise of medical records remains a central focus of the forensic analysis. Healthcare providers using Medyc are advised to monitor for any further updates regarding data exposure as the investigation progresses.



