Skip to main content

Polish dental software vendor FELG reports patient data breach and ransom demand

0
High
Published: 10/01/2026 (10/01/2026, 19:16:21 UTC)
Source: Reddit Cybersecurity

Description

Polish dental software vendor FELG Dent suffered a data breach involving patient records and received a ransom demand. An attacker exploited insecure API endpoints to access sensitive patient and staff data, including personal identifiers and medical information. FELG estimates about 2 million patient records were affected. The attacker claims to hold about 10% of the database and threatens to sell it on a dark web forum after failed ransom negotiations. FELG has notified Polish authorities and is assisting affected dental practices with breach notifications under GDPR.

Reddit Discussion

r/cybersecurity·posted by u/Horror-Web-1584
00

FELG Software sp. z o.o., the Polish maker of the FELG Dent application for dental practices, told customers on October 1, 2026, that it had been attacked. In a statement on the company's status page, CEO Grzegorz Stawarz said an attacker claiming to belong to the "Fingerprint" group may have accessed patient data that dental practices had entrusted to FELG for processing. The attacker says he holds about 10% of the database and wants a ransom to keep it unpublished. FELG has notified the prosecutor's office and contacted UODO, Poland's data protection authority.

The company's preliminary estimate is around 2 million affected patient records. That figure is based partly on the attacker's own claims. The records include:

  • names, addresses and PESEL numbers (Poland's national identification number)
  • medical data
  • information related to e-prescriptions
  • e-ZLA records (electronic sick-leave certificates)
  • eWUŚ checks (the system practices use to verify a patient's public health insurance)

FELG notes that the number of records doesn't necessarily match the number of people. It expects results from its log analysis within a few days. The company says it knows how the breach happened but won't disclose technical details.

What the attacker claims

The attacker, who calls himself Horus, contacted two Polish IT security news sites, Sekurak and Zaufana Trzecia Strona (Z3S). He told Sekurak he had data on 2.4 million felgdent.com patients. He said this included PESEL numbers, names, addresses, phone numbers, NIP tax identification numbers and each patient's dental practice. He also claimed 1.2 million prescriptions, visit records, e-ZLA records, eWUŚ tables, files and photographs.

He also claimed 712,000 staff records. FELG denied that figure immediately, and he lowered it to 28,000, blaming duplicate records. Sekurak received a sample of data on several well-known people but could not confirm it was genuine, since it might have come from earlier breaches. Z3S gave the attacker the PESEL numbers of eight people who had agreed to the test. None of them were in his database.

According to Z3S, Fingerprint had nothing to do with the attack, and the group itself confirmed this. The attacker admitted to Z3S that he had brought up the attacks on MyDr and Medyc when talking to FELG to make his ransom demand more intimidating.

His account of the method is a textbook IDOR (insecure direct object reference) flaw. He says he created a demo account and found API endpoints that didn't check authorization. By incrementing a query parameter, he could pull successive patients, prescriptions and doctors. He says he started downloading data on September 6. FELG told Z3S it learned of the incident on September 28 at around 6 p.m.

The attacker also says the attack was spotted after several days and the faulty endpoint was fixed. He claims he then found other endpoints with the same flaw and kept using them for a while. None of this is verified, and FELG isn't commenting on technical details. Because FELG broke off negotiations and went public, he says he will sell the database on Cebulka, a Polish-language dark web forum.

How big is FELG?

Sources disagree. Sekurak cited 16,000 dental practices. FELG's website claims more than 4,000 practices, more than 16,000 doctors and hygienists, and more than 12 million patient records. Z3S, also going by the website, reads the 16,000 figure as dentists using FELG's tools. Z3S says the leak may involve more than 2 million people. In its statement to Sekurak, FELG spoke of about 2 million records.

What affected practices should know

Under GDPR, a practice using FELG Dent is the data controller for its patients' data, and FELG is its processor. FELG has asked customers not to report the breach to the President of UODO (the head of the authority) until it formally confirms whether a given practice is affected. After the weekend, affected practices are due to receive a ready-made UODO notification and a free tool for notifying patients. The other practices will get confirmation that their data was not affected.

Article in Polish here: https://pelnomocnikcyber.pl/aktualnosci/felg-dent-incydent-dane-pacjentow/

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 19:31:12 UTC

Technical Analysis

FELG Software sp. z o.o., maker of the FELG Dent application used by dental practices in Poland, disclosed a data breach on October 1, 2026. The attacker, self-named Horus, exploited insecure direct object reference (IDOR) vulnerabilities in the FELG Dent API, allowing unauthorized access to patient and staff data by incrementing query parameters without proper authorization checks. The attacker began data exfiltration on September 6 and was detected on September 28. The compromised data includes names, addresses, PESEL numbers, medical data, e-prescriptions, electronic sick-leave certificates, and health insurance verification records. The attacker claims to hold about 10% of the database and demands ransom to prevent publication. FELG denies some attacker claims and has notified the prosecutor's office and Poland's data protection authority (UODO). The company is providing affected dental practices with tools and notifications to comply with GDPR breach reporting requirements.

Potential Impact

Approximately 2 million patient records containing sensitive personal and medical information were potentially exposed. This includes national identification numbers (PESEL), addresses, medical records, e-prescriptions, electronic sick-leave certificates, and health insurance verification data. The breach also involved some staff records, although the exact number is disputed. The exposure of such data poses significant privacy risks to affected individuals and may lead to identity theft, fraud, and reputational damage to FELG and its customers. The attacker’s ransom demand and threat to sell the data on a dark web forum increase the risk of further unauthorized disclosure.

Defensive Guidance

FELG has fixed the insecure API endpoints that allowed unauthorized data access. The company has notified relevant Polish authorities, including the prosecutor's office and the data protection authority (UODO). Dental practices using FELG Dent are advised to await formal confirmation from FELG regarding whether their data was affected before reporting the breach to UODO. FELG is providing affected customers with ready-made breach notifications and tools to notify patients as required under GDPR. No additional public technical details or patches have been disclosed. Practices should follow FELG’s guidance and regulatory requirements for breach notification.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Newsworthiness Assessment
{"score":43,"reasons":["external_link","newsworthy_keywords:data breach,breach","urgent_news_indicators","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":["data breach","breach"]}
Has External Source
true
Trusted Domain
false

Threat ID: 6abeb4f9a43b0b3b89ee1869

Added to database: 10/01/2026, 19:31:05 UTC

Last enriched: 10/01/2026, 19:31:12 UTC

Last updated: 10/02/2026, 04:15:59 UTC

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses