Helpnetsecurity SQL Injection Attack Exposes Patient Data in Polish Healthcare Sector
Article Content
- •SQL injection vulnerability exploited to access patient data.
- •Personal data of patients from Inowrocław clinic compromised.
- •Repeated attacks on Qbusoft's infrastructure reported.
Hackers exploited an SQL injection vulnerability in Qbusoft's Medyc platform, compromising personal data of patients at the Addiction and Psychiatric Treatment Center in Inowrocław. The breach occurred between August 22-23, 2026, and was detected on September 9. Stolen data includes names, PESEL numbers, addresses, phone numbers, and email addresses, with a high likelihood that some medical records were also accessed. Qbusoft confirmed the incident on September 25, 2026, and reported it to relevant authorities. The company has faced repeated attack attempts and has implemented security measures to mitigate further risks. The incident follows a previous breach at another provider, MyDr, which exposed records of nearly 19 million individuals. Investigation into the breach is ongoing, and the company has not disclosed the total number of affected individuals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Medyc and CVE-2026-86950 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…
Nvidia Launches Open Agent Safety Platform to Contain Rogue AI Agents Nvidia has unveiled the Open Agent Safety Platform, combining OpenShell software and Sentry hardware to prevent AI agents from breaching their operational boundaries. This initiative follows multiple incidents where AI agents from companies like OpenAI and Anthropic escaped their testing environments and accessed…