News / Cybersecurity
SQL Injection Flaw in Qbusoft’s Medyc: Polish Medical Data Exposed in August 2024 Published on 28 September 2026 by Christ-loisele (3 min read)
An SQL injection vulnerability in Qbusoft’s Medyc software allowed cybercriminals to access personal and medical patient data in Poland. Polish authorities are investigating and tightening security requirements following this breach.
A critical flaw exploited in August 2024
Attackers exploited an SQL injection vulnerability in the Medyc platform, developed by Qbusoft , in August 2024, according to The Record and Hazetec . This flaw enabled the extraction of sensitive data, including names, national identification numbers (PESEL), addresses, phone numbers, email addresses, and potentially patients’ medical records . While Qbusoft has not confirmed the theft of medical data, a specialized care center, the Addiction and Psychiatric Treatment Center in Inowrocław, reported that its patients undergoing day treatment were affected.
The encrypted database archive was transferred out of Qbusoft’s systems at the end of August, before the vulnerability was patched on September 9, 2024 , the date the attack was detected. Despite the immediate fix, Medyc’s infrastructure continued to face repeated attack attempts, causing service disruptions.
Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk
Illustration: Lawing Tech
A group claiming responsibility for the attack linked to a previous breach
A group claiming responsibility for this intrusion, linked to the previous breach at MyDr , contacted a Polish cybersecurity-focused media outlet, according to The Record . This connection suggests a targeted campaign against actors in Poland’s healthcare sector. The compromised data includes hospital records of patients treated between 2024 and 2026 at the Inowrocław center, heightening concerns over long-term impacts on medical record confidentiality.
Polish Digital Affairs Minister Krzysztof Gawkowski criticized Qbusoft for not initially reporting the incident to CERT Polska , emphasizing that corporate silence worsens risks for citizens. This omission led to an investigation by the Central Bureau for Combating Cybercrime and an audit order from Poland’s data protection authority.
Authorities’ reactions and regulatory tightening
In response to this flaw and the MyDr breach, Polish authorities are considering stricter measures , including mandatory security certifications for healthcare actors and stricter rules on data processing, as reported by Hazetec . These developments could serve as a model for other countries facing similar risks in the healthcare sector.
Qbusoft has acknowledged in a statement that the attacks could lead to website slowdowns and access restrictions to certain modules , without specifying whether these disruptions persist. The platform remains under pressure, however, with recurring intrusion attempts.
What this changes here
For healthcare facilities and public administrations in Benin and West Africa, this intrusion underscores the urgency of strengthening security audits of systems handling sensitive data, particularly medical records. The Polish example shows that delayed detection and correction times can worsen the consequences of a breach, while lack of transparency with competent authorities exposes citizens to increased risks.
Countries in the region could draw lessons from these events to accelerate the adoption of strict regulatory frameworks , such as mandatory incident reporting requirements or minimum security standards for critical software. Additionally, training technical teams to detect vulnerabilities, such as SQL injections, and raising awareness among IT leaders about emergency procedures could mitigate the impact of such attacks.
Finally, collaboration with local cybersecurity bodies , such as the CERT-Benin , could enable a faster and coordinated response in the event of a major breach, thus avoiding the delays observed in Poland.
Sources