SQL Injection Breach at Qbusoft Exposes Up to 5 Million Polish Patients’ Records
What Happened – Attackers exploited a SQL‑injection flaw in Qbusoft’s Medyc health‑records application, extracted an encrypted database archive and transferred it outside the provider’s environment. The breach potentially affects up to five million Polish citizens, exposing names, addresses, contact details and PESEL identifiers.
Why It Matters for Trust & Control Assurance
- Highlights the need for continuous third‑party security monitoring and evidence of secure coding practices.
- Demonstrates how a single application‑level control gap can undermine a vendor’s overall trust posture and audit readiness.
- Reinforces the importance of maintaining a defensible audit trail for vendor risk assessments.
Who Is Affected – Polish healthcare providers that rely on Qbusoft’s Medyc platform and the patients whose personal and medical data were stored therein.
Recommended Actions – Re‑evaluate Qbusoft as a critical vendor, request recent vulnerability‑scan reports, verify encryption key‑management processes, and map the incident to your control‑objective framework for audit evidence. Source: https://www.databreachtoday.com/poland-probes-hack-second-health-software-vendor-a-32980
Technical Notes – The exploit was a classic SQL‑injection against the application interface (identified Aug 22‑23). Although the database was encrypted, poor key‑handling allowed attackers to decrypt the data after exfiltration. Exfiltrated fields: name, surname, address, phone, email, and PESEL number. Source: https://www.databreachtoday.com/poland-probes-hack-second-health-software-vendor-a-32980