
Hackers demand 100,000 PLN ransom after breaching Polish dental platform FELG
Cybersecurity authorities in Poland are responding to a breach at dental software supplier FELG Software, where extortionists claim to hold 2.4 million patient records after demanding a 100,000 PLN payment.
Extortion attempt at FELG Software
Cybersecurity teams and state agencies in Poland are investigating an intrusion into the FELG Dent cloud platform, a software system utilized by over 4,000 dental practices and 16,000 medical staff. The cybercrime group known as Horus contacted security outlets and claimed possession of files belonging to 2.4 million patients. According to company statements, the perpetrator demanded a ransom of 100,000 PLN to prevent the publication of the stolen database. FELG Software refused to pay the ransom and notified both the prosecutor's office and the Personal Data Protection Office (UODO). Company chief executive Grzegorz Stawarz stated that internal assessments indicate the compromised data represents roughly 10% of their 12 million patient records.
We regret to inform you that we have also fallen victim to a hacker attack. The person claiming responsibility asserts that they gained access to approximately 10% of our database and is demanding a ransom not to disclose it.
Technical flaw and data exposure
Security analysis published by Niebezpiecznik indicated that the attackers exploited an Insecure Direct Object References (IDOR) flaw within the multi-tenant architecture of FELG Software. This vulnerability allowed direct URL queries to access medical documentation across separate client environments without requiring proper authorization. The perpetrators released a sample of the extracted records containing national identification numbers (PESEL), home addresses, appointment details, and medication histories. Leaked records reportedly included information associated with public figures such as Grzegorz Braun, Janusz Palikot, and the son of politician Sławomir Mentzen. The attackers claimed the full cache spans 700,000 medical staff profiles, 1.2 million prescriptions, diagnostic imaging, and sick leave forms.
- MyDr
- 19000000
- Medyc
- 5000000
- FELG Dent (claimed)
- 2400000
A cascade of medical database breaches
The incident at FELG Dent follows multiple unauthorized intrusions targeting private medical software providers in Poland during September 2026. The sequence began with an attack on MyDr, a subsidiary of DocPlanner, which exposed records for 19 million patients. A separate attack against the Medyc platform developed by Qbusoft compromised personal data for approximately 5 million individuals, while private healthcare provider Enel-Med reported a breach affecting roughly 3% of its patient registry on 25 September. A hacker operating under the name Fingerprint claimed responsibility for the MyDr, Medyc, and Enel-Med intrusions, framing the actions as non-commercial penetration tests. That hacker distanced themselves from the FELG Dent attack and offered technical assistance to FELG Software.
State response and sector statistics
Government monitors at the e-Health Centre Computer Security Incident Response Team (CSIRT CeZ) confirmed that central national health databases remained secure during the breach. CSIRT CeZ registered 1,379 cybersecurity incidents across the health sector between January and the end of September 2026, approaching the 1,441 total incidents recorded throughout 2025. In the 2026 tally, online fraud and social engineering represented 389 cases, security vulnerabilities accounted for 269, credential theft numbered 110, and malware comprised 79. Deputy Health Minister Tomasz Maciejewski noted the broader geopolitical and criminal dimensions of data theft during a briefing on the figures.
Data has become the new gold.
To assist healthcare facilities after an intrusion, the e-Health Centre introduced a mobile response unit equipped with independent power, servers, and network equipment. Polish authorities continue to verify the full scope of the FELG compromise while dental practices evaluate their notification duties under data privacy rules.
- 2022
- 251
- 2025
- 1441
- Jan–Sep 2026
- 1379


