Up to 5 million
Poland's healthcare sector has been struck by another major data breach, this time affecting Qbusoft, the provider of the Medyc medical records platform. Threat actors exploited a critical SQL injection vulnerability to access and exfiltrate a database containing sensitive patient information. The stolen data includes personally identifiable information (PII) such as names and PESEL national identification numbers, with a high probability that detailed clinical documentation was also compromised. This incident follows a recent large-scale breach in Poland's healthcare system, prompting swift action from the country's data protection authority (UODO) and Central Cybercrime Bureau (CBZC), who have launched a formal investigation into Qbusoft's security practices.
The attack vector was a classic but highly effective SQL injection vulnerability in the Medyc application's web interface. According to a notification from an affected clinic, forensic analysis determined that an unauthorized party exploited this flaw between August 22-23, 2026. This vulnerability allowed the attacker to bypass security controls and directly interact with the backend database, enabling them to exfiltrate an encrypted archive of the entire database. This method represents a failure in secure coding practices, specifically in input sanitization, allowing attacker-controlled input to be executed as a database query (T1190 - Exploit Public-Facing Application).
The intrusion was detected on the night of September 8-9, weeks after the data exfiltration occurred. The attackers specifically targeted tables containing medical information, leading investigators to assess that it is 'highly probable' that sensitive clinical records were stolen alongside PII. The full scope of the breach is still under investigation, but media reports suggest the data of up to five million individuals could be involved. The Polish government has criticized Qbusoft for delays in reporting the incident to national cybersecurity authorities like CERT Polska, threatening strict enforcement actions.
The exfiltrated data is highly sensitive, creating significant risk for the affected patients. The compromised information includes:
This data can be used for sophisticated identity theft, fraud, blackmail, and targeted phishing campaigns. The presence of medical information makes the breach particularly severe, as it could expose highly private details about individuals' health. For Qbusoft, the incident carries severe consequences, including significant regulatory fines under GDPR, loss of trust from its client clinics, and potential legal action. The public criticism from government officials further exacerbates the reputational damage.
No specific Indicators of Compromise were mentioned in the source articles.
To hunt for SQL injection activity, security teams should monitor for the following:
...aspx?id=1' OR '1'='1UNION SELECT, --, SLEEP()D3-NTA) to monitor for unusually large data transfers from database servers to external destinations. Database activity monitoring (DAM) tools can also alert on anomalous query structures or access to an abnormally large number of records by a single user.D3-AH).D3-ITF).Implementing secure coding practices, such as input validation and parameterized queries, to prevent injection attacks.
Mapped D3FEND Techniques:
Using a Web Application Firewall (WAF) to filter malicious requests containing SQL injection payloads.
Mapped D3FEND Techniques:
Applying the principle of least privilege to the database account used by the web application to limit the potential damage of a compromise.
Mapped D3FEND Techniques:
The root cause of the Medyc platform breach was a failure in secure coding. The most effective countermeasure is robust application hardening, specifically focused on preventing SQL injection. Developers must adopt a 'never trust user input' mindset. All data received from a client, whether in a URL parameter, form field, or HTTP header, must be rigorously validated and sanitized. The gold standard for preventing SQLi is the exclusive use of parameterized queries (also known as prepared statements). This practice separates the SQL code from the data, ensuring that user-supplied input is always treated as data and never executed as a command. For the Medyc platform, this would mean refactoring all database-interacting code to eliminate any dynamic query string concatenation and replace it with prepared statements. Regular code reviews and static application security testing (SAST) should be integrated into the CI/CD pipeline to automatically flag and fail builds that contain vulnerable code patterns.
To detect SQL injection attempts against web applications like Medyc, continuous URL analysis is essential. This should be implemented at the network edge using a Web Application Firewall (WAF) or a similar intrusion prevention system. The system should be configured with rulesets that inspect the structure and content of incoming HTTP requests for tell-tale signs of SQL injection. This includes looking for SQL keywords (SELECT, UNION, INSERT), comment characters (--, /*), and common injection payloads (' OR 1=1). When a malicious pattern is detected in a URL or POST body, the request should be blocked, and a high-priority alert should be generated for the security operations team. This provides a critical layer of defense that can stop an attack even if the underlying application code is vulnerable. For a healthcare platform like Medyc, these rules should be tuned to minimize false positives while aggressively blocking any request that deviates from the expected format for application endpoints.
Attacker begins exploiting an SQL injection vulnerability in the Medyc platform.
Attacker exfiltrates an encrypted archive of the patient database.
The intrusion is detected by Qbusoft.
An affected clinic notifies its patients of the breach.
Qbusoft makes a public statement about the incident.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.