
Poland investigates Qbusoft medical software breach affecting at least one million patients
The Central Cybercrime Bureau has opened a probe after hackers compromised Qbusoft's Medyc platform, exposing identification numbers and health files from clinics nationwide.
Cybercrime investigation into Qbusoft breach
Poland's Central Cybercrime Bureau (CBZC) has opened an investigation into a cybersecurity breach involving software developer Qbusoft Sp. z o.o., Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski announced on Thursday evening. The Olsztyn-based company produces Medyc, also operating as Medyc.pl, an electronic medical records management application used by medical offices and clinics nationwide. The Medyc software platform processes more than 10,000 patient appointments each day and is deployed across hundreds of healthcare facilities. Investigators and cybersecurity specialists confirmed that unauthorized third parties breached the company's systems, gaining access to an encrypted database archive that contains sensitive personal and medical records.
Compromised patient files and facility notices
The incident became public on Thursday after the Addiction and Psychiatric Treatment Center in Inowrocław issued a formal statement to patients regarding a compromise of its data. The facility disclosed that the breach affected the Day Addiction Treatment Department, exposing patient files recorded between 1 July 2024 and 23 August 2026. According to the center's announcement, the breached records include full names, PESEL identification numbers, residential and registered addresses, telephone numbers, email contacts, and individual health data. Forensic analyses conducted following the discovery indicated that the breach had been contained, with no current evidence of ongoing unauthorized access to the systems. Independent cybersecurity monitoring outlets CyberDefence24 and Zaufana Trzecia Strona reported that the Medyc leak affects hundreds of medical practices across Poland, placing the data of at least one million patients at risk.
Links to MyDr intrusion and perpetrator claims
Cybersecurity researchers linked the intrusion to the same threat actor operating under the pseudonym "fingerprint", who executed an attack on the MyDr medical platform in August 2026. That earlier MyDr breach affected 12,000 healthcare entities and exposed the medical and prescription data of 18 million to 19 million Polish citizens. In online statements published in late August, roughly two weeks after the MyDr disclosure, "fingerprint" foreshadowed further network intrusions while asserting that the exfiltrated records were not intended for ransom demands or darknet sale. The actor claimed to have rejected commercial purchase offers for the stolen databases, stating that the operations were intended to expose systemic vulnerabilities across European digital infrastructure.
Do not call us criminals, our mission is to improve the poor digital security in Europe. Especially now, during the war with Russia.
Software vendor regulations and government response
Minister Gawkowski noted that Qbusoft had not reported the cybersecurity breach to CERT Polska or to CSIRT CeZ, the Computer Security Incident Response Team operating within the e-Health Center. The breach follows regulatory measures taken by the Ministry of Health and CSIRT CeZ, which formulated and distributed updated cybersecurity recommendations to healthcare software providers on 16 September 2026 for mandatory implementation. Gawkowski stated that state agencies would pursue strict enforcement against any commercial software provider found violating statutory cybersecurity protocols.
In case of any breach of safety procedures by a private company, ruthless consequences will be drawn.
- MyDr breach compromises patient and prescription records across 12,000 healthcare entities
- CSIRT CeZ and Health Ministry deliver cybersecurity guidelines to medical software vendors
- Qbusoft Medyc breach disclosed as CBZC opens broader investigation

