Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

SQL Injection Breach Exposes Patient Data from Polish EHR Provider Qbusoft

Hackers exploited an SQL injection flaw in Qbusoft’s Medyc cloud‑based EHR platform, stealing names, national IDs, addresses and likely medical records of patients treated between July 2024 and August 2026. The incident highlights the need for continuous application security controls and auditable remediation evidence for compliance frameworks such as GDPR.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
therecord.media

SQL Injection Breach Exposes Patient Data from Polish EHR Provider Qbusoft

What Happened — Hackers exploited an SQL‑injection flaw in Qbusoft’s Medyc cloud‑based electronic health‑record platform in August 2024. They extracted an encrypted archive containing names, national identification (PESEL) numbers, addresses, phone numbers, email addresses and, likely, medical treatment records of patients treated between July 2024 and August 2026.

Why It Matters for Trust & Control Assurance

  • The incident is a textbook example of why continuous application‑security monitoring and documented vulnerability remediation are core to a control‑assurance program.
  • Evidence of timely patching, permission hardening and credential rotation provides the defensible audit trail required under data‑protection regulations such as GDPR.
  • Mapping the remediation steps to a single control objective (secure development & vulnerability management) satisfies multiple framework requirements simultaneously.

Who Is Affected – Polish healthcare providers that rely on the Medyc platform, and the patients whose personal and treatment data were stored there (e.g., the Addiction and Psychiatric Treatment Center in Inowrocław).

Recommended Actions

  • Perform a rapid application‑security assessment focused on injection vectors across all web interfaces.
  • Verify that the SQL‑injection flaw has been fully remediated and capture timestamps, change logs and test results as audit evidence.
  • Review and tighten database access permissions, enforce least‑privilege principles, and rotate all related credentials.
  • Document the incident response steps in a centralized Trust Center to support continuous monitoring and future audits.

Technical Notes – The attack leveraged a classic SQL injection vulnerability in the Medyc application interface, allowing arbitrary queries against the underlying database. The attackers exfiltrated an encrypted archive, but the encryption key was likely compromised or weak, making decryption feasible. The breach was detected on 9 September 2024, and the vendor applied a patch and additional monitoring the same day. Source: The Record

📰 Original Source
https://therecord.media/poland-cyberattack-medical-medyc ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →