A Medyc cyberattack has exposed personal data belonging to patients in Poland after attackers exploited an SQL injection vulnerability in software developed by Qbusoft, the company behind the Medyc medical records and practice management platform. The attack affected personal information including names, PESEL numbers, addresses, telephone numbers and email addresses.
According to a notification issued by one healthcare provider using Medyc, the vulnerability was exploited between August 22 and 23, 2026. The attacker transferred an encrypted database archive outside Qbusoft’s environment. The incident was detected during the night of September 8 to 9.
How the Medyc Cyberattack Happened
An SQL injection vulnerability can allow an attacker to manipulate an application’s database queries and access information stored in the underlying database.
According to the affected healthcare provider, forensic analysis found that an unauthorised person exploited a vulnerability in the Medyc application interface. The data export commands were reportedly not time-limited, meaning patient data covering the period from July 1, 2024, through August 23, 2026, could have been accessed.
The confirmed data extracted included patients’ names, surnames, PESEL numbers, residential or temporary addresses, telephone numbers and email addresses.
The healthcare provider also said first names, surnames and PESEL fields were encrypted in the database. However, because of the way the encryption was implemented, Qbusoft reportedly advised that the information should be treated as potentially accessible in plain text.
Medical Records Remain Under Investigation
The incident has also raised concerns about access to sensitive medical data.
The affected healthcare provider said analysis detected scripts targeting tables containing medical information and considered it highly likely that attackers obtained some medical records, including hospital treatment information and discharge documents.
However, Qbusoft later provided a different update. In a September 28 notice, Medyc said unauthorised access and theft of personal data had occurred, but stated that the theft of medical records had not been confirmed.
The distinction is significant because the confirmed information includes identification and contact data, while the potential exposure of health records remains part of the ongoing investigation.
Qbusoft Takes Security Measures
Following detection of the attack, Qbusoft said it fixed the exploited vulnerability and cut off the attacker’s access.
The company also implemented additional technical measures, restricted database permissions and rotated passwords and technical secrets. Its infrastructure was placed under continuous monitoring.
Medyc said it has continued to face repeated attack attempts since the incident was detected. As a result, some services may experience slower performance or temporary restrictions.
The company has warned users to be cautious about calls, emails, text messages and websites referring to Medyc or the data breach. Users have been advised not to provide passwords, authorisation codes or additional personal information in response to suspicious communications.
Polish Authorities Investigate the Incident
The incident has been reported to Polish authorities, including the Personal Data Protection Office (UODO) and police. Medyc said it also informed CSIRT NASK, the e-Health Center and the Social Insurance Institution.
Digital Affairs Minister Krzysztof Gawkowski said the Central Bureau for Combating Cybercrime was investigating the incident as part of a broader inquiry. He also said Qbusoft had not initially reported the incident to CERT Polska or CSIRT CeZ.

UODO has said the Medyc incident is being examined and announced plans to inspect Qbusoft. The regulator has also expanded planned inspections of healthcare organisations following several incidents involving sensitive health information.
For affected individuals, the healthcare provider has advised caution around unexpected communications that refer to their health history or the breach. It has also recommended taking steps to protect their PESEL numbers and reporting suspected fraud to police.






































