A second Polish medical software provider has been hit within weeks. Attackers used a SQL injection flaw to steal patient data from Medyc, a platform sold by QBUSoft to medical offices and clinics. The Medyc data breach in Poland PESEL exposure follows a much larger incident in August, and together they show how much risk sits with the vendors behind clinic software, not with the patients whose records they hold.
The details below come from reporting by Help Net Security. Some parts of the original summary were truncated, so this post sticks to what has been confirmed.
What Was Stolen From Medyc
Medyc is a platform that medical offices and clinics use to manage patient registration, records and prescriptions. According to the report, hackers stole patient data from the provider by exploiting a SQL injection vulnerability.
The reporting indicates the stolen information includes contact details and PESEL numbers, the national identification numbers used in Poland. The full scope of the Medyc theft, including how many patients are affected, was not available in the excerpt provided, so we are not going to guess at a figure.
PESEL numbers matter because they are a long-lived identifier. Unlike a password, a person cannot easily change one. When it is combined with a name and contact information, it can be used to make impersonation attempts look more convincing.
How the MyDr Breach Set the Stage
The Medyc incident did not happen in isolation. In August, attackers stole data on nearly 19 million people from MyDr, a Warsaw-based company whose software is used by about 12,000 healthcare facilities. The leaked database there held PESEL numbers as well.
That scale is the important part. A single vendor serving thousands of facilities holds the records of a large share of a country's population in one place. When that vendor is compromised, every clinic that relies on it is affected at once, and patients often have no idea which software their doctor's office uses.
The Medyc case adds a second data point. Two different vendors, two breaches, and both involve the same kind of sensitive identifiers. That pattern suggests that attackers see medical software providers as efficient targets, since one successful intrusion can yield records from many clinics.
Why SQL Injection Keeps Hitting Healthcare Vendors
SQL injection is one of the oldest and best-understood web vulnerabilities. It happens when an application passes user-supplied input into a database query without properly separating data from commands. An attacker can then craft input that changes the query and makes the database return information it should not.
The fix is well known: parameterized queries, input validation, least-privilege database accounts and regular testing. Yet the flaw keeps appearing, especially in software that has grown over many years or that handles many integrations. Healthcare platforms often fit that description, since they process registration forms, prescriptions and record lookups through web-facing components.
The same vulnerability class shows up well outside medicine. Our coverage of attackers exploiting an unpatched GeoServer SQL injection zero-day shows how one type of flaw can be used against very different platforms. The lesson is consistent: when an internet-facing application talks to a database, unsafe queries are a serious risk.
What This Means For You
If you are a patient in Poland, you likely cannot tell whether your clinic uses Medyc, MyDr or another system. That is the core problem. Your data sits with a third party you did not choose, and your own security habits have little influence over how that third party writes its code.
A VPN encrypts traffic between your device and a server. It does not protect a database that a vendor stores and that an attacker reaches through a flaw in the vendor's own application. The same is true of device encryption and strong passwords: they are useful, but they do not stop a vendor-side breach.
What you can do is reduce the damage if your details are misused:
- Treat unexpected calls, texts or emails that mention your health, prescriptions or PESEL with suspicion, even if they seem to know personal details.
- Do not share your PESEL or medical information over unsolicited contact. Contact the clinic through a number you look up yourself.
- Watch for official notices from your clinic or regulators about whether your data was involved.
- Use strong, unique passwords and two-factor authentication on email and financial accounts, since those are common targets after identity data leaks.
- Check your financial and credit-related records for activity you do not recognize.
Key Takeaways
The Medyc data breach in Poland PESEL exposure, coming after the MyDr leak affecting nearly 19 million people, shows that concentrated health-software vendors are single points of failure. Personal tools like a VPN are worth using for private browsing, but they cannot fix a flaw inside a vendor's database. Responsibility for that rests with providers, who need to fix basic issues like SQL injection, and with regulators who oversee them.
For readers, the practical step is vigilance around impersonation and phishing that uses leaked identifiers. To see how the same flaw type is exploited elsewhere, read our report on the GeoServer SQL injection zero-day.




