Cyber attack on FELG Dent: hackers threaten to disclose doctors' data and prescriptions

Cybercriminals attacking the FELG Dent dental practice system are demanding ransom whilst threatening to publish data about dentists and prescriptions. The company confirms the incident and estimates that over 2 million patient records have been compromised.

Cyber attack on FELG Dent: hackers threaten to disclose doctors' data and prescriptions

Cyber attack on dental practice system

Attackers identifying themselves as Horus have infiltrated the FELG Dent application used by Polish dental practices to maintain patient records. According to reports by cybersecurity services, the group is threatening to disclose a list of dentists along with information about prescriptions they have issued for psychotropic medications and stimulants, attempting to extort a ransom payment.

FELG Software, the software producer, confirmed the attack on 1 October. Chief Executive Grzegorz Stawarz told Sekurak that preliminary estimates indicate approximately 2 million patient records were compromised. However, he noted that this figure is based partly on the attackers' claims and requires verification, and the records do not necessarily correspond to the number of affected individuals.

According to Dziennik Gazeta Prawna, the attacker maintains that they began downloading data as early as 6 September, whilst the company became aware of the incident on 28 September. The perpetrator claims to have exploited access control vulnerabilities that allowed data to be read by modifying the identifier in the query. FELG Software has established the attack method but has not disclosed technical details.

The hackers declare they obtained 2.4 million patient records, 1.2 million prescriptions and initially 712 thousand pieces of medical staff data. After the company disputed this last figure, they changed their declaration to 28 thousand, attributing the discrepancy to duplicate records. Cybersecurity experts note that they have not verified the authenticity of the data samples or clarified whether they originate from this specific breach.

Threats against doctors and lack of confirmation of violations

Individuals claiming to be the perpetrators are threatening to publish information about dentists issuing prescriptions for controlled substances, suggesting irregularities in medical practice. However, the available materials do not contain verified findings that would allow assessment of specific cases. The attackers are attempting to use sensitive medical information to apply pressure whilst demanding payment for non-disclosure of the data.

The software producer has highlighted inaccuracies in the figures provided by the perpetrators. The number of 16 thousand practices requires correction—the FELG Software website lists more than 4 thousand practices and more than 16 thousand doctors and dental hygienists using the application.

Actions taken by the company and authorities

FELG Software has notified the prosecutor's office and the Office for Personal Data Protection. The company plans to conduct an analysis to determine which practices and patients were actually affected by the breach. Current notifications to all clients do not confirm a data breach at each individual facility separately.

The attack on FELG Dent is the latest incident involving a medical software provider in Poland, following earlier cases involving MyDr and Medyc. The similarity of events does not alone determine the identity of the perpetrators—hacker groups operating under the name Horus may be unrelated to one another, though they could also represent branches of the same organisation.

Source: Dziennik Gazeta Prawna

Read this article in the original language