Thank you for reading or listening to The Realist Juggernaut. Independent journalism should be accessible to everyone.
A cyberattack against Polish healthcare software provider Qbusoft has resulted in the theft of patient information from systems associated with its Medyc medical software platform, adding another data-security incident to a healthcare sector already facing sustained cyber threats.
Qbusoft, the company behind Medyc, confirmed that attackers gained unauthorized access to personal data and stole information including names, Polish national identification numbers known as PESEL numbers, residential addresses, telephone numbers, and email addresses.
At this stage, Qbusoft has not confirmed that medical documentation itself was stolen. Information released by at least one affected healthcare provider raises concern that medical records may also have been accessed.
The Addiction and Psychiatric Treatment Center in Inowrocław said forensic findings supplied by Qbusoft showed that an unauthorized person exploited an SQL injection vulnerability in the Medyc application interface on August 22 and 23, 2026. The intrusion allowed an encrypted database archive to be transferred outside the provider’s environment.
The attack was detected during the night of September 8 into September 9.
SQL injection is an application-layer vulnerability in which improperly secured database queries can allow specially crafted input to alter commands sent to an underlying database. Depending on the affected application and permissions available to it, exploitation can expose, modify, or extract information stored in connected databases.
In this incident, the vulnerability provided an avenue into a system handling sensitive healthcare information. The Inowrocław treatment center said the affected records involved patients of its Day Treatment Unit for Addiction Treatment and covered the period from July 1, 2024, through August 23, 2026.
The healthcare provider reported that names, surnames, PESEL numbers, addresses, telephone numbers, and email addresses were among the data shown to have been extracted. Some identifying fields, including names and PESEL numbers, had been stored in encrypted form.
According to the treatment center, Qbusoft advised that the structure of the implementation meant those fields should be treated as potentially recoverable by the attacker rather than regarded as safely protected solely because encryption had been applied.
The status of medical documentation requires a separate distinction. Medyc stated in its September 28 security update that theft of medical records had not been confirmed.
The Inowrocław healthcare provider said forensic analysis identified scripts directed at database tables containing medical information. Based on information supplied by Qbusoft, the provider said there was a high probability that some medical documentation was also obtained.
Potentially affected information at that facility included hospital treatment information and discharge documentation. That does not establish that every Medyc user or every patient record stored through the platform was compromised. No confirmed nationwide total of affected patients has been established by the official sources reviewed.
Qbusoft said it corrected the SQL injection vulnerability on the same day the attack was detected and cut off the attacker’s access. The company also restricted database permissions, forced the rotation of passwords and technical secrets, and placed its infrastructure under additional monitoring.
Qbusoft said the incident was reported to law enforcement and Polish data-protection authorities beginning September 9 and September 10.
Medyc later said the Central Bureau for Combating Cybercrime, Poland’s Office for Personal Data Protection, CSIRT NASK, the e-Health Center, and Poland’s Social Insurance Institution had been informed of incidents affecting its systems.
The company said its infrastructure has continued to face repeated attack attempts. As a result, Medyc warned that users could experience slower service and temporary limitations or outages affecting certain modules while additional security measures are applied.
The platform performs functions that can place substantial amounts of patient and healthcare information within the same technology environment.
Medyc supports electronic medical documentation, patient registration, online scheduling, electronic prescriptions, electronic sick-leave documentation, referrals, telemedicine, medical events, administrative processes, and integrations used by healthcare providers. That concentration of services makes access controls around healthcare platforms particularly important.
A compromise involving a central software provider can affect information belonging to multiple healthcare practices rather than a single medical office.
Poland’s Office for Personal Data Protection, known as UODO, has announced an inspection of Qbusoft in response to the Medyc incident.
UODO President Mirosław Wróblewski said the company responsible for the software will be examined as authorities determine how the data was protected and how the breach occurred. The regulator had already expanded scrutiny of health-data security following other incidents in the Polish medical sector during 2026.
Polish authorities have also been investigating a separate breach involving healthcare software provider MyDr. Government officials said that incident potentially affected historical information associated with approximately 18.8 million people and more than 12,000 healthcare facilities.
The MyDr and Medyc incidents are separate breaches involving different software providers. Their proximity has placed additional attention on the security of companies that process medical information on behalf of healthcare organizations.
Poland’s government had warned earlier in 2026 about hostile cyber activity targeting healthcare entities and issued cybersecurity recommendations intended to help organizations identify compromise and strengthen their defenses.
The Medyc incident has now added scrutiny of third-party medical software providers to that broader concern. Healthcare information presents a different risk profile from many ordinary account compromises. A password can be changed and a compromised payment card can be replaced.
A PESEL number, historical medical information, treatment record, address, and other long-term identifying information cannot be replaced as easily.
Combining those records can give criminals material that could potentially be used in identity fraud, targeted phishing, social engineering, impersonation, or attempts to exploit knowledge of a person’s medical history.
Medyc has warned affected users to exercise caution with unexpected telephone calls, text messages, emails, and websites referring to the company, the breach, or requests to confirm personal information. The company has specifically warned users not to provide passwords, authorization codes, or additional personal information in response to unsolicited communications connected to the incident.
Authorities have not publicly attributed the Medyc intrusion to a specific individual or criminal group.
Claims circulated outside official channels concerning the total number of records allegedly taken and the identity of the attackers have not been confirmed by Polish authorities.
For that reason, the confirmed scope remains narrower than some public claims surrounding the breach.
What is established is that an SQL injection vulnerability was exploited, an archive containing database information was removed from Qbusoft’s environment, personal information was stolen, and at least one affected healthcare provider has reported forensic indications that medical-record tables were targeted.
The investigation now centers on determining the complete scope of the data exposure, identifying the attacker or attackers, assessing whether medical documentation was successfully extracted, and examining Qbusoft’s security and incident-handling practices.
For patients, healthcare providers, and Polish regulators, those findings will determine how far the Medyc breach ultimately extends.
Qbusoft sp. z o.o. / Medyc — Data Breach Notice, updated September 28, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



