fingerprint is a pseudonymous and unattributed threat actor name associated in Polish reporting with claimed intrusions affecting Polish healthcare-software providers, including MyDr and Qbusoft’s Medyc platform, and the Fakturownia online invoicing platform. The identity, location, membership, and relationship between the incidents have not been publicly established by Polish authorities. An individual or group using the fingerprint alias claimed responsibility for the Medyc intrusion, in which an SQL-injection vulnerability in a public-facing application was exploited and an encrypted database archive was exfiltrated. Confirmed exposed Medyc data included personal information; potential compromise of clinical data was also under investigation. The actor also claimed responsibility for the MyDr breach and claimed access to Fakturownia data, but public attribution and the full scope and authenticity of the claimed thefts remained unverified. The actor stated that its activities were intended to expose deficient cybersecurity rather than generate financial gain; this stated rationale is unverified.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Claimed responsibility for exploiting a vulnerability to access Fakturownia servers and exfiltrate data, reportedly including invoices and customer information. The actor also claims responsibility for breaches affecting Polish healthcare software providers MyDr and Medyc.
Allegedly conducted the Medyc/Qbusoft breach and was linked by reporting to the separate MyDr healthcare-software breach. The actor reportedly claimed to expose weak security rather than profit, and claimed access to millions of patient records and private photographs.
Pseudonyme d’un individu ou groupe non attribué publiquement, ayant revendiqué l’intrusion contre la plateforme médicale Medyc de Qbusoft après exploitation d’une injection SQL. L’acteur affirme également être lié à la précédente violation de MyDr et déclare agir pour exposer de faibles pratiques de cybersécurité plutôt que pour un bénéfice financier.
Allegedly conducted the intrusion into Qbusoft's Medyc healthcare platform and was previously linked by reporting to the MyDr breach. The actor claimed to have stolen patient records and private photographs, purportedly to expose weak cybersecurity rather than for financial gain; this attribution and the claimed data volumes remain unverified.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.