Skip to content
SQL Injection Attack Exposes Patient Data in Polish Healthcare Sector

SQL Injection Attack Exposes Patient Data in Polish Healthcare Sector

First seen 29 Sep 2026, 11:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 11:09 UTC
  • •SQL injection vulnerability exploited to access patient data.
  • •Personal data of patients from Inowrocław clinic compromised.
  • •Repeated attacks on Qbusoft's infrastructure reported.

Hackers exploited an SQL injection vulnerability in Qbusoft's Medyc platform, compromising personal data of patients at the Addiction and Psychiatric Treatment Center in Inowrocław. The breach occurred between August 22-23, 2026, and was detected on September 9. Stolen data includes names, PESEL numbers, addresses, phone numbers, and email addresses, with a high likelihood that some medical records were also accessed. Qbusoft confirmed the incident on September 25, 2026, and reported it to relevant authorities. The company has faced repeated attack attempts and has implemented security measures to mitigate further risks. The incident follows a previous breach at another provider, MyDr, which exposed records of nearly 19 million individuals. Investigation into the breach is ongoing, and the company has not disclosed the total number of affected individuals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-22
SQL injection attack executed
An unauthorized person exploited a security flaw in Qbusoft's Medyc platform, extracting patient data.
Helpnetsecurity
2026-09-09
Breach detected
Qbusoft detected the unauthorized access to its systems, leading to immediate security measures.
Therecord.Media
2026-09-25
Qbusoft confirms data theft
The company confirmed the breach and the theft of personal data on its website.
Helpnetsecurity
2026-09-28
CVE-2026-86950 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track Medyc and CVE-2026-86950 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed