Join our FREE personalized newsletter for news, trends, and insights that matter to everyone in America

Newsletter
New

Polish Dental Software Vendor Felg Reports Patient Data Breach And Ransom Demand

Card image cap

FELG Software sp. z o.o., the Polish maker of the FELG Dent application for dental practices, told customers on October 1, 2026, that it had been attacked. In a statement on the company's status page, CEO Grzegorz Stawarz said an attacker claiming to belong to the "Fingerprint" group may have accessed patient data that dental practices had entrusted to FELG for processing. The attacker says he holds about 10% of the database and wants a ransom to keep it unpublished. FELG has notified the prosecutor's office and contacted UODO, Poland's data protection authority.

The company's preliminary estimate is around 2 million affected patient records. That figure is based partly on the attacker's own claims. The records include:

  • names, addresses and PESEL numbers (Poland's national identification number)
  • medical data
  • information related to e-prescriptions
  • e-ZLA records (electronic sick-leave certificates)
  • eWUŚ checks (the system practices use to verify a patient's public health insurance)

FELG notes that the number of records doesn't necessarily match the number of people. It expects results from its log analysis within a few days. The company says it knows how the breach happened but won't disclose technical details.

What the attacker claims

The attacker, who calls himself Horus, contacted two Polish IT security news sites, Sekurak and Zaufana Trzecia Strona (Z3S). He told Sekurak he had data on 2.4 million felgdent.com patients. He said this included PESEL numbers, names, addresses, phone numbers, NIP tax identification numbers and each patient's dental practice. He also claimed 1.2 million prescriptions, visit records, e-ZLA records, eWUŚ tables, files and photographs.

He also claimed 712,000 staff records. FELG denied that figure immediately, and he lowered it to 28,000, blaming duplicate records. Sekurak received a sample of data on several well-known people but could not confirm it was genuine, since it might have come from earlier breaches. Z3S gave the attacker the PESEL numbers of eight people who had agreed to the test. None of them were in his database.

According to Z3S, Fingerprint had nothing to do with the attack, and the group itself confirmed this. The attacker admitted to Z3S that he had brought up the attacks on MyDr and Medyc when talking to FELG to make his ransom demand more intimidating.

His account of the method is a textbook IDOR (insecure direct object reference) flaw. He says he created a demo account and found API endpoints that didn't check authorization. By incrementing a query parameter, he could pull successive patients, prescriptions and doctors. He says he started downloading data on September 6. FELG told Z3S it learned of the incident on September 28 at around 6 p.m.

The attacker also says the attack was spotted after several days and the faulty endpoint was fixed. He claims he then found other endpoints with the same flaw and kept using them for a while. None of this is verified, and FELG isn't commenting on technical details. Because FELG broke off negotiations and went public, he says he will sell the database on Cebulka, a Polish-language dark web forum.

How big is FELG?

Sources disagree. Sekurak cited 16,000 dental practices. FELG's website claims more than 4,000 practices, more than 16,000 doctors and hygienists, and more than 12 million patient records. Z3S, also going by the website, reads the 16,000 figure as dentists using FELG's tools. Z3S says the leak may involve more than 2 million people. In its statement to Sekurak, FELG spoke of about 2 million records.

What affected practices should know

Under GDPR, a practice using FELG Dent is the data controller for its patients' data, and FELG is its processor. FELG has asked customers not to report the breach to the President of UODO (the head of the authority) until it formally confirms whether a given practice is affected. After the weekend, affected practices are due to receive a ready-made UODO notification and a free tool for notifying patients. The other practices will get confirmation that their data was not affected.

Article in Polish here: https://pelnomocnikcyber.pl/aktualnosci/felg-dent-incydent-dane-pacjentow/

submitted by /u/Horror-Web-1584
[link] [comments]