CTIPilot

Qbusoft Medyc healthcare-software breach (Poland, September 2026)

incident · incident:qbusoft-medyc-poland-breach-2026-09

Qbusoft Sp. z o.o.'s Medyc practice-management software, used by Polish medical clinics, was breached via SQL injection on 22-23 August 2026; the company discovered the intrusion on 8-9 September but made no public statement of its own, and the breach surfaced via a patient facility's own notice in late September. Zaufana Trzecia Strona attributes it to the same actor ('fingerprint') behind August's MyDr breach and reports Qbusoft never notified Poland's healthcare-sector CERT or CERT Polska (Zaufana Trzecia Strona, 2026-09-24/25).

Aliases: Medyc breach, Qbusoft breach

Coverage timeline
1
first 2026-09-27 → last 2026-09-27
Peak priority
notable
1 notable
Sources cited
4
3 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

2 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-27/qbusoft-medyc-poland-healthcare-breach-fingerprint-actor · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-09-27/qbusoft-medyc-poland-healthcare-breach-fingerprint-actor · ATT&CK page ↗

Story timeline

  1. 2026-09-27Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection by the same actor behind August's over-18-million-patient MyDr leak
    active-threatsA second Polish health-records vendor falls to the same actor, and it never told the national CERT

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed to

Where this entity is cited

  • active-threats1

Source distribution

  • zaufanatrzeciastrona.pl2 (50%)
  • databreaches.net1 (25%)
  • tvpworld.com1 (25%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Qbusoft Medyc healthcare-software breach (Poland, September 2026) (1)

2026-09-27 · view entry permalink →

NOTABLENATOB2

Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection by the same actor behind August's over-18-million-patient MyDr leak

Qbusoft Sp. z o.o., the Polish company behind the Medyc practice-management application used by medical clinics across the country, was breached via an SQL-injection vulnerability on 22-23 August 2026; the attackers exfiltrated an "encrypted database archive," per the Inowrocław facility's own breach notice (Zaufana Trzecia Strona, 2026-09-24). Qbusoft itself did not learn of the intrusion until the night of 8-9 September, roughly two and a half weeks later, and had made no public statement of its own as of this reporting, even in response to ZTS's direct press questions sent days earlier; the breach surfaced instead when the Addiction and Psychiatric Treatment Center in Inowrocław notified its own patients that their data had leaked from the Medyc system, the same facility that had earlier notified patients of the unrelated MyDr leak (Zaufana Trzecia Strona, 2026-09-24). Stolen fields include name, surname, national PESEL identity number, residential address, phone number and email address; per the facility's own notice, the name, surname and PESEL fields were stored encrypted, but the vendor had told the facility the encryption was easy to break, so the attackers could still reach that data, and ZTS assesses there is a good chance medical discharge-summary data was taken as well (Zaufana Trzecia Strona, 2026-09-24).

Zaufana Trzecia Strona, the outlet that first revealed August's MyDr breach of more than 18 million Polish patients' records, identifies the actor behind both intrusions as the same self-styled group or individual using the pseudonym "fingerprint": "The perpetrators of the leak are the same people who were behind the attack on the MyDr systems, from which the data of over 18 million Poles was stolen" (translated from Polish) (Zaufana Trzecia Strona, 2026-09-24). A follow-up ZTS post relays the attackers' own claim of far greater scale than the outlet's initial estimate: "we ourselves assessed the scale of the incident at at least a million people; according to the perpetrators it is five million. The perpetrators also mention that they stole 8 million \"very private\" photos" (translated from Polish) (Zaufana Trzecia Strona, 2026-09-25); ZTS states plainly it could not confirm the claimed photo count reached the perpetrators, though it does not dispute that photos of some kind may have been taken, and DataBreaches.net separately notes that whether this is genuinely the same attacker "has not been disclosed" from its own reporting vantage (DataBreaches.net, 2026-09-26); treat the same-actor link as ZTS's own attribution, not an independently confirmed fact. A second ZTS source states that, as with MyDr, Qbusoft's main company resources were stored in cloud services, specifically Microsoft Azure infrastructure, unlike MyDr's AWS-hosted environment (Zaufana Trzecia Strona, 2026-09-25).

Poland's Digital Affairs Minister Krzysztof Gawkowski confirmed the incident and disclosed a notification gap: although Qbusoft reported the intrusion to the Central Office for Combating Cybercrime, it never passed information to CSIRT CEZ, the CERT established specifically for the healthcare sector, or to CERT Polska, the national CERT that coordinated the MyDr incident and holds Poland's deepest incident-response experience (Zaufana Trzecia Strona, 2026-09-25). As of this reporting, the attackers had not published or offered the stolen data for sale, consistent with their pattern after the MyDr breach.

According to information we have, a new large leak of personal and medical data has occurred, this time from the systems of Qbusoft Sp. z o.o., the maker of the Medyc.pl practice application. The perpetrators of the leak are the same people who were behind the attack on the MyDr systems, from which the data of over 18 million Poles was stolen. (translated from Polish)

The Addiction and Psychiatric Treatment Center in Inowrocław reported having received information about a leak of its patients' data from the Medyc system (the same center had earlier reported a leak of its patients' data from the MyDr system, which is bad luck). (translated from Polish)

As we read in the Inowrocław facility's own notice, the attack on Qbusoft took place on 22-23 August of this year. The perpetrators, using an SQL Injection vulnerability, stole an "encrypted database archive." The company learned of the incident on the night of 8-9 September. (translated from Polish)

we ourselves assessed the scale of the incident at at least a million people; according to the perpetrators it is five million. The perpetrators also mention that they stole 8 million "very private" photos. (translated from Polish)

The incident at Qbusoft was also confirmed by Minister Gawkowski, who pointed out that although the victim of the attack informed the Central Office for Combating Cybercrime about it, it did not pass information to either the CSIRT CEZ team, established to handle incidents in the healthcare sector, or to the CERT Polska team, which coordinates the largest incidents and has the greatest experience in Poland in this regard (it handled, among others, the coordination of the incident at MyDr). (translated from Polish)

Zaufana Trzecia Strona 2026-09-24

Whether it’s the same attacker or whether any ransom demand has been involved has not been disclosed.

DataBreaches.net 2026-09-26

Builds on: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap

incident27 Sep 04:34Zmulti-sourceOpen finding ↗