Data Breaches

Polish Medyc Breach Exposes Patient IDs After SQL Injection Went Unnoticed

Polish Medyc Breach Exposes Patient IDs After SQL Injection Went Unnoticed

An attacker exploited a SQL injection flaw in the application interface of Medyc, a cloud platform Polish clinics use for medical records, e-prescriptions and scheduling on 22 and 23 August and copied an encrypted archive of its database. The platform’s developer, Qbusoft, detected the intrusion on the night of 8 to 9 September, more than two weeks later.

Medyc said on 25 September that the confirmed stolen data covers names, PESEL national identification numbers, home addresses, phone numbers and email addresses. It has not confirmed the theft of medical records. One of its customers has published a notice that goes further.

The Odwykowo-Psychiatryczny Ośrodek Leczniczy in Inowrocław, an addiction and psychiatric treatment centre, told patients that Qbusoft’s forensic findings showed scripts had been run against database tables holding medical data. The vendor described the theft of hospital discharge summaries as very likely. Patients of the centre’s day unit for addiction treatment are affected for the whole period from 1 July 2024 to 23 August 2026, because the export commands had no time limit.

The Encryption Qbusoft Told Customers to Discount

Names, surnames and PESEL numbers were stored encrypted. According to the Inowrocław notice, Qbusoft told customers to assume the attackers could read them anyway because of how the code was built. Encryption that the vendor itself tells you to disregard is not a control.

Qbusoft closed the injection flaw on the day it found the attack, the centre says, then restricted database permissions, rotated every password and technical secret and put the infrastructure under continuous monitoring. It reported the incident to the police cybercrime unit on 9 September and to UODO, the Polish data protection office, on 10 September.

Zaufana Trzecia Strona reports that Medyc runs on Microsoft Azure and that its developer has described the cloud as the answer to security problems. An injectable API is injectable wherever it is hosted.

Five Million Patients Is the Attackers’ Figure

A person or group calling itself “fingerprint” contacted Zaufana Trzecia Strona after the publication’s first report on 24 September claimed responsibility and said it had taken records on 5 million patients and 8 million private photographs. The publication, which had put the number affected at a minimum of 1 million, could not verify either figure.

Treat the 5 million figure as a claim from the party with the most reason to inflate it until Qbusoft or UODO publishes a count. It has already travelled a long way. UODO’s own announcement of its audit opened by citing media reports of up to five million affected Poles, reports that trace back to the people who took the data.

Zaufana Trzecia Strona had previously linked the “fingerprint” name to the MyDr breach, and Polish broadcaster RMF FM reported that the MyDr attackers were likely behind Medyc too, according to The Record. The claimants say their aim was to expose weak security, not to make money. Polish authorities have attributed the breach to no one and the data has not been published.

Reported to the Police, Not to the Incident Responders

Digital Affairs Minister Krzysztof Gawkowski said on 24 September that the Central Bureau for Combating Cybercrime is investigating the Medyc attack as part of a broader inquiry and that Qbusoft had not reported the incident to CERT Polska or to CSIRT CeZ, the health sector’s incident response team. “Hiding attacks by companies is the biggest mistake, as it always puts citizens at risk,” he said as reported by The Record.

Medyc’s statement, last updated on 25 September, the day after the minister spoke, says the company has reported the incidents regularly to services including the cybercrime bureau, UODO, CSIRT NASK and Centrum e-Zdrowia. It gives no dates.

One date sits awkwardly in that timeline. On 16 September, a week after Qbusoft detected the breach, CSIRT CeZ and the Ministry of Health sent healthcare software vendors security recommendations prompted by attacks on medical providers and their suppliers according to the minister’s statement as published by UODO. Zaufana Trzecia Strona called Qbusoft’s decision to bypass both incident teams strange since their help is free.

Poland Wants Certification for Medical Software Suppliers

The Medyc breach follows one at MyDr, whose software connects providers to Poland’s national P1 e-health platform. MyDr disclosed its intrusion in August and Polish authorities say it may involve data on nearly 19 million people and more than 12,000 medical facilities. The Inowrocław centre was a customer of both.

UODO president Mirosław Wróblewski has ordered an audit of Qbusoft, as he did with MyDr. By 17 September his office had received more than 50 complaints and over 2,000 notifications from data controllers about MyDr. On 16 September he ordered additional audits of health data processing to run until the end of 2026.

Gawkowski said on 26 September that the government is preparing rules that would require security certification and restrict how private companies process medical data.

If a supplier holds your patient or customer records, put one question to it before the next contract renewal: how long would a bulk export of your data go unnoticed? In practice, Qbusoft’s answer was more than two weeks.

References

  1. Cyberattack on Polish Medical Software Provider Exposes Patient Data
  2. Informacja dotycząca naruszenia bezpieczeństwa danych
  3. Zawiadomienie o naruszeniu ochrony danych osobowych
  4. Miliony Polaków poszkodowane. Po nowym wycieku danych medycznych PUODO zapowiada kontrolę
  5. Sprawcy ataku na system Medyc twierdzą, że ukradli dane 5 milionów pacjentów i 8 milionów zdjęć
  6. Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million People

This post is also available in: Svenska

Per Häggdahl

Per Häggdahl is Head of Business Unit and CISO at eBuilder Security, with more than 20 years securing systems for banks, central banks, stock exchanges and central securities depositories, now leading the team that brings that same enterprise-grade protection to organisations of every size.