Security · October 1, 2026
Enel-Med Confirms Cyberattack and Data Breach
Enel-Med S.A. officially confirmed that it became a victim of a cyberattack, resulting in a breach of data confidentiality. As stated in a statement:
"The management of Enel-Med Medical Center S.A. ("Issuer") informs that on September 24, 2026, in the evening hours, it received information about an IT security incident and a breach of the Company's data confidentiality."
At this time, the details of the attack and the extent of the data affected by the breach are not known. The company reported that it took immediate actions to secure its IT infrastructure and customer data.
National authorities and institutions have been informed about the incident, including the Central Cybercrime Bureau (CBZC), the CSIRT team led by the e-Health Center, the President of the Personal Data Protection Office (UODO), and CERT Poland.
So far, no hacking group has publicly claimed responsibility for the attack on Enel-Med's infrastructure. It is likely that details will take time to emerge until findings from the investigations are published, if they are published at all.
It is also worth noting that recent days have not been the best for the Polish healthcare system. The echoes of a serious leak from the MyDr systems are still resonating, while reports of further attacks are surfacing. Although there is no official link between the attackers, it cannot be ruled out that they are the same perpetrators or acting on behalf of the same entity.
Until an official statement is released, standard security measures are recommended.