Cyberattack on Polish medical software provider Qbusoft exposes patient data
An attacker exploited an SQL injection flaw in Qbusoft's Medyc medical records platform in late August and exfiltrated an encrypted database archive. Names, PESEL numbers, addresses, phone numbers and emails were stolen, with medical records possibly affected. The intrusion was detected on September 9 and the vulnerability was patched the same day.
- SQL injection in Medyc's interface was exploited in late August
- Stolen data includes names, PESEL numbers, addresses, phones and emails
- Intrusion detected overnight on September 9, flaw patched immediately
- Attackers claimed 5 million patients and 8 million photos, unverified
Read next
Security