Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Qbusoft Cyberattack Exposes Sensitive Patient Data as Polish Regulators Investigate

Qbusoft Cyberattack Exposes Sensitive Patient Data as Polish Regulators Investigate

By: Jordan Vector — Cybersecurity Expert

Last updated: September 30, 2026

Human Written
Qbusoft Cyberattack Exposes Sensitive Patient Data as Polish Regulators Investigate
  • Hackers broke into Qbusoft, a Polish company that builds software for hospitals and clinics, and stole patient data.

  • The stolen files include patient names, national ID numbers, home addresses, phone numbers, and emails.

  • Some reports claim millions of patients were hit, but nobody has confirmed that number yet.

A cyberattack on Qbusoft has put patient information at risk across Poland. Qbusoft builds Medyc, a cloud-based platform that many clinics use every day. Doctors use Medyc for patient records, appointment booking, diagnoses, prescriptions, and referrals.

The company confirmed the breach, and Polish officials have now opened an investigation. Regulators also plan to audit Qbusoft’s security systems, according to The Record.

How the Hackers Broke In

The attacker found a weak spot in Qbusoft’s software back in August. This flaw is called an SQL injection vulnerability. It let the hacker slip past normal security checks. Once inside, the attacker pulled an encrypted database out of Qbusoft’s systems. Nobody at the company noticed right away, according to The Record.

Staff finally spotted the intrusion during the night of September 8 to 9. By then, more than two weeks had already passed. Qbusoft moved fast once it found the problem. The company patched the flaw, tightened database permissions, and changed passwords and login credentials. It also added extra monitoring to catch future threats early, according to The Record.

Patient Records End Up in the Wrong Hands

Qbusoft confirmed that hackers took real patient information. The stolen data includes full names and PESEL numbers, which work like Polish national ID numbers. Home addresses, phone numbers, and email addresses were also taken.

One affected clinic, the Addiction and Psychiatric Treatment Center in Inowrocław, said the stolen records cover patients treated at its day unit. That covers patients treated between July 2024 and August 2026, according to The Record.

There are also signs that medical files may have been touched. The Inowrocław center said investigators found scripts aimed at database tables holding medical information. Hospital treatment notes and discharge summaries may be part of that exposure.

However, Qbusoft has not confirmed that medical records were actually stolen. This gap matters a lot. Confirmed data theft and suspected medical file access do not carry the same level of proof right now, according to The Record.

Online reports claim the hacker stole data from as many as five million patients. Some posts even claim eight million private photos were taken. A person claiming responsibility for the attack shared these numbers. Nobody has independently confirmed either figure. Polish police have not named a suspect or hacking group yet. The stolen files have also not shown up publicly online, according to The Record.

Polish Authorities Step In

Poland’s Central Bureau for Combating Cybercrime is now investigating the breach. It forms part of a wider inquiry into the attack. Digital Affairs Minister Krzysztof Gawkowski confirmed that officials are reviewing exactly how the breach happened. Poland’s data protection office, known as UODO, announced its own audit of Qbusoft. UODO president Mirosław Wróblewski will lead that review, according to UODO.

The way Qbusoft reported the breach has also drawn criticism. Minister Gawkowski said Qbusoft failed to alert CERT Polska right away. He also said the company did not immediately contact CSIRT CeZ, Poland’s healthcare incident response team. Qbusoft has pushed back on this claim. The company says it actually reported the breach to several security groups and authorities, according to The Record.

This attack follows a separate breach at MyDr, another Polish healthcare software provider. Other institutions in Poland have also faced recent data breaches, including the University of Warsaw breach that exposed student and staff data.

That earlier incident may have affected close to nineteen million people, according to The Record. Two major healthcare breaches within weeks of each other have worried experts. Many now question how well Polish medical software companies protect patient data.

Security experts often repeat the same advice after breaches like this. Patients should watch for strange calls, emails, or messages that mention their medical visits. They should also report anything unusual to their clinic right away. Clinics, for their part, need faster detection systems. Two full weeks passed before Qbusoft even noticed the intrusion. That gap gave the attacker plenty of time to move data freely.

For now, patients connected to the affected clinics face real uncertainty. Confirmed facts show that personal details were stolen. Claims about stolen medical records and huge patient numbers remain unverified. Polish authorities say their investigation is ongoing, and more updates are expected soon.

Share this article

You might also like

ZachXBT Says Bitget Hack Launderers Seek Help in Public Chat Rooms

ZachXBT Says Bitget Hack Launderers Seek Help in Public Chat Rooms

Blockchain investigator ZachXBT says Chinese groups are helping move stolen crypto from the Bitget hack. Bitget confirmed hackers stole $387.5…

September 30, 2026
Health PEI Data Breach May Expose Personal Information of 234,000 People

Health P.E.I. Data Breach May Expose Personal Information of 234,000 People

Health P.E.I. states that an online security issue may impact a number of people up to 234,000. An unauthorized person…

September 30, 2026
Hacker Claims 8.6 Million French Patient Records Linked to Alaxione

Hacker Claims 8.6 Million French Patient Records Linked to Alaxione

A seller says a second file tied to French health tech firm Alaxione holds about 8.6 million patient records. The…

September 28, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.