Beyond Fakturownia. Other cyberattack announcements
Enel-med, PUZ in Suwałki, Zdrowit and Inowrocław alongside Fakturownia. What is known about the incidents, and what do they mean for customers and businesses?

Article summary
Fakturownia is one of several organizations whose security incidents were reported in late September 2026. Announcements and reports also concerned enel-med, the State University of Applied Sciences in Suwałki (PUZ), Zdrowit S.A. and patient data from an addiction treatment unit in Inowrocław. They describe different consequences: access to data, encrypted systems and the theft of an archive.
The publication dates are not the dates of all the attacks. The Inowrocław case goes back to August, while the date of the incident at Zdrowit has not been given. For a customer, the key questions concern the data affected and the next recommendations. For a business, system access, the ability to restore operations and contact with the provider are equally relevant. Below, we compare the findings available on September 30, 2026.
Contents
When were the incidents disclosed and detected?
When reading an announcement, distinguish the date of the incident, its detection and the publication of information. The known dates in this comparison are listed below. All dates in the table refer to 2026.
| Organization or case | Announcement or report | Known incident or detection date | Findings |
|---|---|---|---|
| Fakturownia | September 29 | Detected on September 28; the start of the attack was not specified. | The operator confirms unauthorized access to servers and is investigating the extent of the data breach. |
| Enel-med | September 27 | Cyberattack identified on September 24. | Access to some patient data. According to the company, the breach may affect around 3% of its database. |
| PUZ in Suwałki | September 29 | Attack date not specified. | Server infrastructure encrypted; access to backups also lost. High risk of access to personal data. |
| Zdrowit S.A. | September 24 | Attack date not specified. | The company confirms unauthorized access to IT systems and the encryption of some resources. |
| Addiction treatment unit in Inowrocław / Medyc | September 24, center's notification and CyberDefence24; September 28, Medyc update | According to the notification, theft on August 22 and 23, detected during the night of September 8 to 9. | Confirmed theft of personal data. The center considers the theft of discharge summaries very likely; Medyc does not confirm the theft of medical records. |
Fakturownia and business data
In its announcement of September 29, Fakturownia said that it had detected unauthorized access to its servers the previous day. The potentially affected information includes company and user account data, password hashes, session, API and integration tokens generated by Fakturownia, bank account numbers and payment data. The operator also lists counterparty data and some invoice data.
This concerns sign-in credentials, connections between applications and transaction information. We describe specific actions for users in Fakturownia data breach - what to do?. Here, Fakturownia serves as a reference point for incidents in other sectors.
Enel-med confirms access to some patient data
In its announcement of September 27, enel-med said that it had identified a cyberattack and access to some patient data on September 24. According to the company, the breach may affect around 3% of its entire database. This is a preliminary estimate while the investigation continues; the announcement gives neither the number of people nor a detailed list of affected data fields.
The operator said it would contact each patient whose data had been affected individually, providing information and recommendations. It also stated that all its facilities were operating normally and that appointments could be booked through the application and call center.
For patients, these are two separate pieces of information. Appointments going ahead concern access to treatment. A breach notification concerns data confidentiality. Being able to book an appointment does not replace the promised information about an individual's situation.
The university in Suwałki also lost access to its backups
The Prof. Edward F. Szczepanik State University of Applied Sciences in Suwałki published an announcement on September 29. It reported a ransomware attack, which uses software to demand a ransom, and the encryption of its server infrastructure. It lost access to its systems and their backups, including student and employee databases, student administration systems, and HR and payroll systems.
The university warned of a high risk of unauthorized access to personal data. It listed first and last names, PESEL numbers (Polish national identification numbers), addresses, grades and bank account numbers, among other information.
Despite these problems, PUZ said that the academic year would start on October 1 and classes would follow their schedules. For other organizations, this is a concrete reason to check whether systems can be restored and how staff will receive information if the usual tools stop working.
Check who can access your business data
If you work in a KSeFGPT organization and manage its permissions, review the groups and the operations available to employees.
Open KSeFGPTZdrowit distinguishes the company incident from pharmacy systems
On September 24, CyberDefence24 published a statement from Zdrowit S.A., which Alert Medyczny subsequently covered. The company confirmed unauthorized access to IT systems and the encryption of some resources. CyberDefence24 also reported that a ransomware group had already listed Zdrowit among its victims in early September. The date of the attack itself remains unspecified.
The company explicitly distinguished its systems from those of Apteki Zdrowit pharmacies. According to its statement, the pharmacies are separate entities using dedicated specialist software that was not affected by the incident. Keep that scope in mind when assessing the consequences for your own pharmacy or order. A shared name alone does not establish which systems were attacked.
The Inowrocław case concerns a theft in August
In its notification concerning the Medyc data breach, the addiction and psychiatric treatment center in Inowrocław reported a cyberattack on the system of its data processor: Qbusoft, the developer of the Medyc software. CyberDefence24 also reported on the case on September 24. The Medyc section of the notification concerns patients of the day addiction treatment unit.
According to the notification, the encrypted database archive was stolen on August 22 and 23, and the incident was detected during the night of September 8 to 9. The scope covers patients of the day treatment unit from July 1, 2024, to August 23, 2026. The center states that the extraction of first names, last names, PESEL numbers, residential or temporary addresses, phone numbers and email addresses was conclusively proven.
The center states that first names, last names and PESEL numbers were stored in encrypted form, but the provider instructed recipients to assume that they were easy to decrypt and that attackers had obtained them in plaintext. The notification also describes scripts targeting tables containing medical data and an assessment that the theft of hospital discharge summaries is very likely. This is the provider's assessment as reported by the center.
In its announcement updated on September 28 at 08:26, Medyc confirms the theft of personal data and lists the same categories of identifying and contact information. It also states that the theft of medical records had not been confirmed at that stage. The center's notification and Medyc's announcement agree on the theft of personal data; the assessment of the risk of discharge summaries being obtained must be distinguished from confirmation of the theft of medical records.
This case illustrates the software provider's role in the overall data processing chain. An organization needs information about more than its own computers; it also needs to know about the systems in which its service provider stores or processes data.
What should customers and businesses check?
As a customer, patient or student, follow the organization's official announcement and notifications addressed to you. Check which group of people, period and types of data the information concerns. Verify urgent requests to sign in, provide information or make a payment using a phone number or website address you already know.
Enel-med recommends unique passwords, two-factor authentication and caution with emails, text messages and calls. Enel-med and PUZ also recommend using Poland's procedure to block the use of your PESEL number. These actions help reduce further risks; changing a password does not remove data someone has already copied.
Within your business, establish who receives provider announcements and makes decisions about access. Check whether the data you need can be restored, when this was last tested and how you will contact your team without the main system. Distinguish the end of an operational interruption from determining what information may have been taken.
An access review should also cover unused integrations. If you use KSeFGPT, the guide to deleting an integration explains how to remove its configuration and saved credentials from the application. This requires the appropriate permissions and the Automation module. Revoking a token with its issuer is a separate operation.
Match invoice permissions to people's tasks
Someone who reads documents for accounting and an employee who handles sales may need different levels of access. When organizing business accounts, start with the tasks people perform, then check each person's permissions.
In a KSeFGPT organization, an authorized user can configure groups and assign them to active members. The guide to setting group permissions and assigning a group to a user describes this process in the context of the selected company. Review these settings when an employee's responsibilities change.
Frequently asked questions
Did all the cyberattacks described here happen in late September 2026?
No. Late September is when the announcements and reports discussed here were published. Fakturownia gave September 28 as the detection date, and enel-med gave September 24. The notification from the center in Inowrocław identifies August 22 and 23 as the dates of the archive theft. The announcements concerning PUZ in Suwałki and Zdrowit do not specify the dates of the attacks themselves.
Was a data leak confirmed in every one of these incidents?
The findings differ. Enel-med confirmed unauthorized access to some patient data, PUZ warned of a high risk of access, and Zdrowit confirmed access to its systems and the encryption of some resources. The center in Inowrocław and Medyc confirm the theft of personal data. The center's notification describes the theft of discharge summaries as very likely, while Medyc's announcement of September 28 does not confirm the theft of medical records. Fakturownia was still investigating the extent of the data affected.
Did the cyberattack on Zdrowit affect pharmacy systems?
According to the statement from Zdrowit S.A. published by CyberDefence24 on September 24, 2026, the specialist software used by Apteki Zdrowit pharmacies was not affected by the incident. The company said that the pharmacies are separate entities. This statement concerns the scope of this particular incident; it is not a general assessment of every pharmacy's security.
Does a working service mean that customer data is safe?
Service availability and data confidentiality are separate issues. In its announcement of September 27, 2026, enel-med reported both access to some patient data and the normal operation of its facilities. Being able to book an appointment or sign in to an application does not establish whether someone previously gained unauthorized access to data.
Recommended reading
Further guidance on the incident and reviewing access:
Fakturownia data breach - what to do?
How to set group permissions and assign a group to a user in KSeFGPT
Organize your team's access to invoices
If you manage permissions in a KSeFGPT organization, assign employees to groups that match their tasks and review their access to business invoices.
Sign in to KSeFGPTSources
Information as of September 30, 2026. The announcements describe the findings and statements of the individual organizations. The Inowrocław section draws on the center's notification, Medyc's announcement and CyberDefence24's report. CyberDefence24 also quotes Zdrowit's statement, while Alert Medyczny summarizes the same publication about the company.
- Fakturownia: incident announcement of September 29, 2026
Fakturownia · accessed: 2026-09-29
Detection date and the possible extent of the data breach reported by the operator.
- Enel-med medical center announcement of September 27, 2026
Centrum Medyczne ENEL-MED S.A. · accessed: 2026-09-29
Unauthorized access, a possible scope of around 3% of the database, planned contact with patients and information on facility operations.
- Advanced cyberattack on the university's IT network
Państwowa Uczelnia Zawodowa w Suwałkach · accessed: 2026-09-29
September 29 announcement on encrypted infrastructure, unavailable systems and backups, and the risk of access to data.
- Zdrowit S.A. confirms a cyberattack. What about pharmacy systems?
Alert Medyczny · accessed: 2026-09-29
September 24 report based on CyberDefence24's coverage of the company's statement.
- Cyberattack on Zdrowit. The company confirms
CyberDefence24 / Oskar Klimczuk · accessed: 2026-09-29
September 24 report containing the full statement from Zdrowit S.A., including the distinction between company systems and separate pharmacies.
- Patient data stolen from an addiction treatment center. A flaw in medical software
CyberDefence24 / Oskar Klimczuk · accessed: 2026-09-30
September 24 report quoting the Inowrocław center's notification, the timeline of the archive theft and the assessment of the risk of data being read.
- Personal data breach notification: the Medyc section
Odwykowo-Psychiatryczny Ośrodek Leczniczy w Inowrocławiu · accessed: 2026-09-30
Original notification covering day treatment unit data, theft and detection dates, and the assessment of the risk of discharge summaries being obtained. The page has separate MyDr and Medyc sections.
- Medyc: information about the data security breach
Qbusoft sp. z o.o. / Medyc · accessed: 2026-09-30
Announcement updated on September 28, 2026, at 08:26: confirmed theft of personal data; theft of medical records not confirmed at that stage.