Qbusoft's Medyc practice-management software, used by Polish healthcare providers, is breached via SQL injection by the same actor behind August's over-18-million-patient MyDr leak
A second Polish health-records vendor falls to the same actor, and it never told the national CERT
Analysis
Qbusoft Sp. z o.o., the Polish company behind the Medyc practice-management application used by medical clinics across the country, was breached via an SQL-injection vulnerability on 22-23 August 2026; the attackers exfiltrated an "encrypted database archive," per the Inowrocław facility's own breach notice (Zaufana Trzecia Strona, 2026-09-24). Qbusoft itself did not learn of the intrusion until the night of 8-9 September, roughly two and a half weeks later, and had made no public statement of its own as of this reporting, even in response to ZTS's direct press questions sent days earlier; the breach surfaced instead when the Addiction and Psychiatric Treatment Center in Inowrocław notified its own patients that their data had leaked from the Medyc system, the same facility that had earlier notified patients of the unrelated MyDr leak (Zaufana Trzecia Strona, 2026-09-24). Stolen fields include name, surname, national PESEL identity number, residential address, phone number and email address; per the facility's own notice, the name, surname and PESEL fields were stored encrypted, but the vendor had told the facility the encryption was easy to break, so the attackers could still reach that data, and ZTS assesses there is a good chance medical discharge-summary data was taken as well (Zaufana Trzecia Strona, 2026-09-24).
Zaufana Trzecia Strona, the outlet that first revealed August's MyDr breach of more than 18 million Polish patients' records, identifies the actor behind both intrusions as the same self-styled group or individual using the pseudonym "fingerprint": "The perpetrators of the leak are the same people who were behind the attack on the MyDr systems, from which the data of over 18 million Poles was stolen" (translated from Polish) (Zaufana Trzecia Strona, 2026-09-24). A follow-up ZTS post relays the attackers' own claim of far greater scale than the outlet's initial estimate: "we ourselves assessed the scale of the incident at at least a million people; according to the perpetrators it is five million. The perpetrators also mention that they stole 8 million \"very private\" photos" (translated from Polish) (Zaufana Trzecia Strona, 2026-09-25); ZTS states plainly it could not confirm the claimed photo count reached the perpetrators, though it does not dispute that photos of some kind may have been taken, and DataBreaches.net separately notes that whether this is genuinely the same attacker "has not been disclosed" from its own reporting vantage (DataBreaches.net, 2026-09-26); treat the same-actor link as ZTS's own attribution, not an independently confirmed fact. A second ZTS source states that, as with MyDr, Qbusoft's main company resources were stored in cloud services, specifically Microsoft Azure infrastructure, unlike MyDr's AWS-hosted environment (Zaufana Trzecia Strona, 2026-09-25).
Poland's Digital Affairs Minister Krzysztof Gawkowski confirmed the incident and disclosed a notification gap: although Qbusoft reported the intrusion to the Central Office for Combating Cybercrime, it never passed information to CSIRT CEZ, the CERT established specifically for the healthcare sector, or to CERT Polska, the national CERT that coordinated the MyDr incident and holds Poland's deepest incident-response experience (Zaufana Trzecia Strona, 2026-09-25). As of this reporting, the attackers had not published or offered the stolen data for sale, consistent with their pattern after the MyDr breach.
Cited evidence
According to information we have, a new large leak of personal and medical data has occurred, this time from the systems of Qbusoft Sp. z o.o., the maker of the Medyc.pl practice application. The perpetrators of the leak are the same people who were behind the attack on the MyDr systems, from which the data of over 18 million Poles was stolen. (translated from Polish)
The Addiction and Psychiatric Treatment Center in Inowrocław reported having received information about a leak of its patients' data from the Medyc system (the same center had earlier reported a leak of its patients' data from the MyDr system, which is bad luck). (translated from Polish)
As we read in the Inowrocław facility's own notice, the attack on Qbusoft took place on 22-23 August of this year. The perpetrators, using an SQL Injection vulnerability, stole an "encrypted database archive." The company learned of the incident on the night of 8-9 September. (translated from Polish)
we ourselves assessed the scale of the incident at at least a million people; according to the perpetrators it is five million. The perpetrators also mention that they stole 8 million "very private" photos. (translated from Polish)
The incident at Qbusoft was also confirmed by Minister Gawkowski, who pointed out that although the victim of the attack informed the Central Office for Combating Cybercrime about it, it did not pass information to either the CSIRT CEZ team, established to handle incidents in the healthcare sector, or to the CERT Polska team, which coordinates the largest incidents and has the greatest experience in Poland in this regard (it handled, among others, the coordination of the incident at MyDr). (translated from Polish)
Whether it’s the same attacker or whether any ransom demand has been involved has not been disclosed.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.