Threat Bulletin TLP WHITE: Data Breach at Polish Dental Software Vendor FELG Software (FELG Dent)

On October 1, 2026, FELG Software sp. z o.o., the Polish developer of FELG Dent, a cloud-based practice management application for dental practices, confirmed a cybersecurity incident affecting its platform. The incident became public when a threat actor using the alias Horus contacted Polish cybersecurity news outlets claiming access to data stored in FELG Dent. According to the company's website, more than 16,000 dentists use its tools. 

FELG Software became aware of the incident on September 28, 2026, and the threat actor demanded a ransom in exchange for not disclosing the stolen data. Because FELG Dent serves many independent dental practices from a single platform, a compromise of the vendor may affect patients across a large number of unrelated health sector organizations.

This incident represents the third attack in the last three months against health sector software vendors in Poland, following MyDr in August 2026, where the Ministry of Digital Affairs estimated that data on 18.8 to 19 million people may have been affected, and Medyc (Qbusoft) in September 2026. Unlike the two earlier incidents, the FELG Dent breach involves a different threat actor pursuing ransom and the sale of stolen data.

View the detailed report below.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272