Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

SQL Injection Breach at Qbusoft Exposes Up to 5 Million Polish Patients’ Records

Attackers exploited a SQL‑injection flaw in Qbusoft’s Medyc platform, extracting an encrypted database that contained personal and medical data for up to five million Polish citizens. The incident underscores the need for continuous vendor risk monitoring and audit‑ready evidence of application security controls.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
databreachtoday.com

SQL Injection Breach at Qbusoft Exposes Up to 5 Million Polish Patients’ Records

What Happened – Attackers exploited a SQL‑injection flaw in Qbusoft’s Medyc health‑records application, extracted an encrypted database archive and transferred it outside the provider’s environment. The breach potentially affects up to five million Polish citizens, exposing names, addresses, contact details and PESEL identifiers.

Why It Matters for Trust & Control Assurance

  • Highlights the need for continuous third‑party security monitoring and evidence of secure coding practices.
  • Demonstrates how a single application‑level control gap can undermine a vendor’s overall trust posture and audit readiness.
  • Reinforces the importance of maintaining a defensible audit trail for vendor risk assessments.

Who Is Affected – Polish healthcare providers that rely on Qbusoft’s Medyc platform and the patients whose personal and medical data were stored therein.

Recommended Actions – Re‑evaluate Qbusoft as a critical vendor, request recent vulnerability‑scan reports, verify encryption key‑management processes, and map the incident to your control‑objective framework for audit evidence. Source: https://www.databreachtoday.com/poland-probes-hack-second-health-software-vendor-a-32980

Technical Notes – The exploit was a classic SQL‑injection against the application interface (identified Aug 22‑23). Although the database was encrypted, poor key‑handling allowed attackers to decrypt the data after exfiltration. Exfiltrated fields: name, surname, address, phone, email, and PESEL number. Source: https://www.databreachtoday.com/poland-probes-hack-second-health-software-vendor-a-32980

📰 Original Source
https://www.databreachtoday.com/poland-probes-hack-second-health-software-vendor-a-32980 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →