Polish dental software vendor FELG reports patient data breach and ransom demand
Polish dental software vendor FELG Dent suffered a data breach involving patient records and received a ransom demand. An attacker exploited insecure API endpoints to access sensitive patient and staff data, including personal identifiers and medical information. FELG estimates about 2 million patient records were affected. The attacker claims to hold about 10% of the database and threatens to sell it on a dark web forum after failed ransom negotiations. FELG has notified Polish authorities and is assisting affected dental practices with breach notifications under GDPR.
AI Analysis
Technical Summary
FELG Software sp. z o.o., maker of the FELG Dent application used by dental practices in Poland, disclosed a data breach on October 1, 2026. The attacker, self-named Horus, exploited insecure direct object reference (IDOR) vulnerabilities in the FELG Dent API, allowing unauthorized access to patient and staff data by incrementing query parameters without proper authorization checks. The attacker began data exfiltration on September 6 and was detected on September 28. The compromised data includes names, addresses, PESEL numbers, medical data, e-prescriptions, electronic sick-leave certificates, and health insurance verification records. The attacker claims to hold about 10% of the database and demands ransom to prevent publication. FELG denies some attacker claims and has notified the prosecutor's office and Poland's data protection authority (UODO). The company is providing affected dental practices with tools and notifications to comply with GDPR breach reporting requirements.
Potential Impact
Approximately 2 million patient records containing sensitive personal and medical information were potentially exposed. This includes national identification numbers (PESEL), addresses, medical records, e-prescriptions, electronic sick-leave certificates, and health insurance verification data. The breach also involved some staff records, although the exact number is disputed. The exposure of such data poses significant privacy risks to affected individuals and may lead to identity theft, fraud, and reputational damage to FELG and its customers. The attacker’s ransom demand and threat to sell the data on a dark web forum increase the risk of further unauthorized disclosure.
Mitigation Recommendations
FELG has fixed the insecure API endpoints that allowed unauthorized data access. The company has notified relevant Polish authorities, including the prosecutor's office and the data protection authority (UODO). Dental practices using FELG Dent are advised to await formal confirmation from FELG regarding whether their data was affected before reporting the breach to UODO. FELG is providing affected customers with ready-made breach notifications and tools to notify patients as required under GDPR. No additional public technical details or patches have been disclosed. Practices should follow FELG’s guidance and regulatory requirements for breach notification.
Polish dental software vendor FELG reports patient data breach and ransom demand
Description
Polish dental software vendor FELG Dent suffered a data breach involving patient records and received a ransom demand. An attacker exploited insecure API endpoints to access sensitive patient and staff data, including personal identifiers and medical information. FELG estimates about 2 million patient records were affected. The attacker claims to hold about 10% of the database and threatens to sell it on a dark web forum after failed ransom negotiations. FELG has notified Polish authorities and is assisting affected dental practices with breach notifications under GDPR.
Reddit Discussion
FELG Software sp. z o.o., the Polish maker of the FELG Dent application for dental practices, told customers on October 1, 2026, that it had been attacked. In a statement on the company's status page, CEO Grzegorz Stawarz said an attacker claiming to belong to the "Fingerprint" group may have accessed patient data that dental practices had entrusted to FELG for processing. The attacker says he holds about 10% of the database and wants a ransom to keep it unpublished. FELG has notified the prosecutor's office and contacted UODO, Poland's data protection authority.
The company's preliminary estimate is around 2 million affected patient records. That figure is based partly on the attacker's own claims. The records include:
- names, addresses and PESEL numbers (Poland's national identification number)
- medical data
- information related to e-prescriptions
- e-ZLA records (electronic sick-leave certificates)
- eWUŚ checks (the system practices use to verify a patient's public health insurance)
FELG notes that the number of records doesn't necessarily match the number of people. It expects results from its log analysis within a few days. The company says it knows how the breach happened but won't disclose technical details.
What the attacker claims
The attacker, who calls himself Horus, contacted two Polish IT security news sites, Sekurak and Zaufana Trzecia Strona (Z3S). He told Sekurak he had data on 2.4 million felgdent.com patients. He said this included PESEL numbers, names, addresses, phone numbers, NIP tax identification numbers and each patient's dental practice. He also claimed 1.2 million prescriptions, visit records, e-ZLA records, eWUŚ tables, files and photographs.
He also claimed 712,000 staff records. FELG denied that figure immediately, and he lowered it to 28,000, blaming duplicate records. Sekurak received a sample of data on several well-known people but could not confirm it was genuine, since it might have come from earlier breaches. Z3S gave the attacker the PESEL numbers of eight people who had agreed to the test. None of them were in his database.
According to Z3S, Fingerprint had nothing to do with the attack, and the group itself confirmed this. The attacker admitted to Z3S that he had brought up the attacks on MyDr and Medyc when talking to FELG to make his ransom demand more intimidating.
His account of the method is a textbook IDOR (insecure direct object reference) flaw. He says he created a demo account and found API endpoints that didn't check authorization. By incrementing a query parameter, he could pull successive patients, prescriptions and doctors. He says he started downloading data on September 6. FELG told Z3S it learned of the incident on September 28 at around 6 p.m.
The attacker also says the attack was spotted after several days and the faulty endpoint was fixed. He claims he then found other endpoints with the same flaw and kept using them for a while. None of this is verified, and FELG isn't commenting on technical details. Because FELG broke off negotiations and went public, he says he will sell the database on Cebulka, a Polish-language dark web forum.
How big is FELG?
Sources disagree. Sekurak cited 16,000 dental practices. FELG's website claims more than 4,000 practices, more than 16,000 doctors and hygienists, and more than 12 million patient records. Z3S, also going by the website, reads the 16,000 figure as dentists using FELG's tools. Z3S says the leak may involve more than 2 million people. In its statement to Sekurak, FELG spoke of about 2 million records.
What affected practices should know
Under GDPR, a practice using FELG Dent is the data controller for its patients' data, and FELG is its processor. FELG has asked customers not to report the breach to the President of UODO (the head of the authority) until it formally confirms whether a given practice is affected. After the weekend, affected practices are due to receive a ready-made UODO notification and a free tool for notifying patients. The other practices will get confirmation that their data was not affected.
Article in Polish here: https://pelnomocnikcyber.pl/aktualnosci/felg-dent-incydent-dane-pacjentow/
Links cited in this discussion
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
FELG Software sp. z o.o., maker of the FELG Dent application used by dental practices in Poland, disclosed a data breach on October 1, 2026. The attacker, self-named Horus, exploited insecure direct object reference (IDOR) vulnerabilities in the FELG Dent API, allowing unauthorized access to patient and staff data by incrementing query parameters without proper authorization checks. The attacker began data exfiltration on September 6 and was detected on September 28. The compromised data includes names, addresses, PESEL numbers, medical data, e-prescriptions, electronic sick-leave certificates, and health insurance verification records. The attacker claims to hold about 10% of the database and demands ransom to prevent publication. FELG denies some attacker claims and has notified the prosecutor's office and Poland's data protection authority (UODO). The company is providing affected dental practices with tools and notifications to comply with GDPR breach reporting requirements.
Potential Impact
Approximately 2 million patient records containing sensitive personal and medical information were potentially exposed. This includes national identification numbers (PESEL), addresses, medical records, e-prescriptions, electronic sick-leave certificates, and health insurance verification data. The breach also involved some staff records, although the exact number is disputed. The exposure of such data poses significant privacy risks to affected individuals and may lead to identity theft, fraud, and reputational damage to FELG and its customers. The attacker’s ransom demand and threat to sell the data on a dark web forum increase the risk of further unauthorized disclosure.
Defensive Guidance
FELG has fixed the insecure API endpoints that allowed unauthorized data access. The company has notified relevant Polish authorities, including the prosecutor's office and the data protection authority (UODO). Dental practices using FELG Dent are advised to await formal confirmation from FELG regarding whether their data was affected before reporting the breach to UODO. FELG is providing affected customers with ready-made breach notifications and tools to notify patients as required under GDPR. No additional public technical details or patches have been disclosed. Practices should follow FELG’s guidance and regulatory requirements for breach notification.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":43,"reasons":["external_link","newsworthy_keywords:data breach,breach","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["data breach","breach"]}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6abeb4f9a43b0b3b89ee1869
Added to database: 10/01/2026, 19:31:05 UTC
Last enriched: 10/01/2026, 19:31:12 UTC
Last updated: 10/02/2026, 04:15:59 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.