CyberSecurity SEE

Poland Investigates Breach of Second Health Software Provider

Poland Investigates Breach of Second Health Software Provider

Investigation Launched After Cyberattack on Poland’s Qbusoft Healthcare Software Vendor

In a troubling escalation of cybercrime, Polish authorities are currently investigating a cyberattack on Qbusoft, a prominent vendor responsible for the healthcare software Medyc. This incident is particularly alarming, occurring just weeks after a significant breach involving MyDr, which impacted approximately 19 million people, nearly half the country’s population.

The Polish government has indicated that the incident involving Qbusoft may affect up to an additional 5 million individuals, compounding the already critical situation following the MyDr breach. Qbusoft, in a public statement released earlier this week, disclosed that it has faced “frequent and repeated attack attempts” from cybercriminals. The firm is actively working to enhance its security measures and maintain service continuity, yet it has cautioned users that these ongoing attacks may result in slower website performance and possible temporary unavailability of specific features. Notably, as of now, Qbusoft has not confirmed any theft of medical records.

In light of the situation, Qbusoft has urged patients to be vigilant against potential phishing attempts, which may arise in the wake of the breach. The company is advising individuals to refrain from disclosing sensitive information—such as passwords or authorization codes—when approached via phone, text, or email regarding matters related to the Medyc platform or a data leak.

Meanwhile, one of Qbusoft’s clients, the Drug Addiction and Psychiatric Treatment Center located in Inowroclaw, has released a breach notice to its patients, offering further insights into the circumstances surrounding the attack. According to the center, forensic specialists have determined that an unauthorized entity exploited a security flaw within the application interface, specifically a SQL injection vulnerability, around August 22-23. This vulnerability led to the unauthorized transfer of an encrypted database archive outside of Qbusoft’s systems, with the incident being identified on the night of September 8-9.

The details of the compromised data are concerning; the stolen information reportedly includes personal identifiers such as names, addresses, phone numbers, email addresses, and PESEL numbers—unique identifiers essential for various tasks in Poland, including rental agreements and utility bills. Although details like names and PESEL numbers were stored in an encrypted format, a structural code flaw allowed the attackers to potentially decrypt this data, raising fears of unauthorized access to sensitive personal information.

Further analysis revealed that attackers likely executed scripts targeting tables containing medical data, suggesting a possibility that medical documentation and hospital treatment records were also compromised. Due to the severity and scope of this breach, it poses a heightened risk to the rights and freedoms of individuals whose personal data has reportedly been obtained unlawfully.

Polish cybersecurity firm Zaufana Trzecia Strona has indicated that the threat actor involved in the Qbusoft incident appears to be the same group that claimed responsibility for the MyDr attack, which is aligned with a pattern of escalating cyberattacks on crucial sectors within Poland. On September 25, Poland’s Deputy Prime Minister and Minister of Digitization, Krzysztof Gawkowski, announced that the Central Bureau for Combating Cybercrime is examining both the Qbusoft incident and the earlier MyDr breach as interconnected events.

In response to increasing threats against medical software providers, Gawkowski revealed that security recommendations were formulated and distributed to healthcare software firms on September 16. He emphasized that any breaches of security procedures by private companies will result in serious consequences.

Both the Qbusoft and MyDr incidents are now under review by Poland’s Office for Personal Data Protection. This office has received over 50 complaints and reports regarding the MyDr breach alone, which resulted in the compromise of 2.5 terabytes of sensitive data, including citizens’ PESEL numbers. The technical and organizational security measures employed by the affected organizations will be meticulously inspected to evaluate their efficacy and adherence to established protocols regarding patient health data.

While the recent cyberattacks targeting Poland’s medical technology sector have not been definitively linked to any nation-state actors, the growing frequency of such breaches has been exacerbated in recent months by suspected Russian hacktivist activities. The Polish Foreign Minister, Radoslaw Sikorski, cautioned that Russia may be gearing up for an expansive operation, which could entail a false-flag attack to justify further aggression beyond Ukraine.

As Poland grapples with these alarming cyber threats, both governmental authorities and healthcare providers must remain diligent in safeguarding sensitive information and maintaining public trust. Only time will tell how effectively these vulnerabilities are addressed and what long-term implications these incidents will have on the nation’s healthcare cybersecurity landscape.

Source link

Exit mobile version