Poland's healthcare sector breaches expose nearly 38M patient records
A fortnight of hacks battered Poland's medical sector — and the official numbers don't add up. Qbusoft flagged ~5 million patient records compromised. Intelligence suggests the true haul was closer to 19 million, exfiltrated via an unpatched SQL injection on its Medyc platform between July 2024 and August 2026. The company reported it September 25 — three weeks after detection. It wasn't alone. MyDr exposed ~18.8 million PESEL IDs through an XXE flaw; Enel-Med leaked ~3% of patient data via compromised credentials. Three vendors, three vectors, same systemic rot. Enforcement until December 2026 now covers every healthcare SaaS vendor. GDPR fines could hit €20 million. The weakest link decided the security posture — and chose to lose the data first. 🔐
Here's a thought. You get hacked, 5 million people's data gets swiped, and you... just sort of go about your day. Not a call to regulators. Not a whisper to the patients. Just business as usual.
That was Qbusoft Sp. z o. o., the medical software firm at the center of Poland's latest cybersecurity meltdown. The company didn't report its incident. It took the authorities — specifically the Inspector General for Personal Data Protection (UODO) — to come knocking on September 25 to make things official. By then, the damage was baked in. And as it turns out, the "damage" was roughly four times bigger than the company would have you believe.
Let's run the numbers, because the scale here is genuinely breathtaking — and the official narrative is, shall we say, economical with the truth.
The Fortnight of Data Leaks
- August 12–13 — MyDr, the popular doctor-booking platform, gets breached. Official line: roughly 19 million Poles' health data and PESEL national ID numbers exposed across some 12,000 medical entities. The grim detail nobody leads with: attackers got in earlier — August 5 — through an XXE vulnerability that gave them remote code execution on MyDr's AWS infrastructure, and exfiltrated EMR databases containing an alleged 18,814,422 unique PESEL entries. They even had the audacity to email the CEO a password-protected PDF of the stolen goods. Charming.
- September 24 — Enel-Med, one of Poland's largest private healthcare providers, suffers a cyberattack. Attackers gain access to patient data, with approximately 3% of the full patient database leaked. The company at least had the decency to notify the CBZC, CSIRT CeZ, CERT Polska, and UODO — after the fact, of course.
- September 25 — Qbusoft confirmed hit. Official estimated impact: 5 million. But hold on.
Here's where the story gets interesting. Because the intelligence available suggests Qbusoft's actual haul was closer to 19 million patient records, stolen via SQL injection on August 22–23 during use of its Medyc platform — exfiltration running from July 2024 to August 2026. The attack was detected September 8–9. Qbusoft reported it September 25. Do the math on that gap. That's not a rounding error in reporting; that's a choice.
The "That'll Teach 'Em" Response
Now for the regulatory theater. Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski has announced "enforcement actions." UODO is inspecting. The Ministry of Health and CSIRT CeZ published "response guidance."
Here's the kicker: broader mandatory safeguards now apply to every healthcare SaaS vendor until December 2026. Not just the three companies that got hit — all of them. That's what we in the business call closing the stable door after the horses have bolted, stampeded through a glass factory, and posted their location on Instagram.
The Part Nobody Wants to Discuss
The telling detail is how these breaches happened. Reports indicate the Enel-Med attack exploited compromised credentials. MyDr fell to an XXE hole in its certificate pipeline. Qbusoft succumbed to an unpatched SQL injection. Three different vendors, three different attack vectors, same systemic rot: a sector that treats data protection like a compliance checkbox rather than an operating principle.
And here's the part that should make everyone uneasy: the same week Poland was transcribing its healthcare data into ransom notes, AWS disclosed [CVE-2026-89049] as a critical vulnerability allowing attackers to bypass port forwarding restrictions and steal temporary IAM credentials from EC2 instances via SSRF. Compromised instances become proxy ladders into internal networks. So the cloud foundation atop which much of this "modern," patient-first healthcare data storage sits has a whopper of its own. But sure — let's have another working group about spreading awareness.
And under GDPR, both Enel-Med and Qbusoft could face fines up to €20 million. That's the theoretical ceiling. Whether the Polish regulator actually lands near that figure is another question entirely — historically, the EU's enforcement has been... let's call it "gentle."
The Projection
Here's the uncomfortable forecast. The MyDr breach exposed roughly 18.8 million identities in August. Qbusoft may have added another 19 million in September. We're not talking about a one-off; we're talking about a pattern of healthcare providers treating personal medical data as a low-priority export.
The prosecutorial attention is real, and it's overdue. But the systems that allowed these breaches — the certificate handling, the SQL hygiene, the reporting discipline, the security posture — are only as strong as the weakest vendor in the chain.
And right now, the weakest link just saved millions of people's data a hell of a lot of trouble. By losing it. Then waiting three weeks to say anything.
Comments ()