Poland is dealing with what its own digital affairs minister called an "unprecedented" cybersecurity incident: an intrusion into MyDr, one of the country's largest electronic medical records (EMR) platforms, in which attackers claim to have taken personal and health data covering nearly 19 million people. Digital Affairs Minister Krzysztof Gawkowski told a Wednesday press conference that "as confirmed by the company itself, 19 million records were stolen, containing various types of data that can be linked together," and ruled out negotiation: "Nobody will negotiate with anyone. Nobody will give in to any blackmail." The attackers themselves claim a precise figure of 18,814,422 unique PESEL national ID numbers, a number relayed to Polish outlets by the security site Zaufana Trzecia Strona (ZTS). For scale, Poland's population is roughly 37 million, so the claimed victim set is on the order of half the country.
What Happened
The affected platform is MyDr, an EMR system used by thousands of Polish clinics, practices and individual doctors. Gazeta Lekarska reports the platform handles roughly 3 million visits and 2.7 million prescriptions per month. Poland Daily 24 notes MyDr belongs to the same corporate group as the consumer-facing appointment platform ZnanyLekarz.
Accounts differ on how firmly the breach is confirmed, and that gap matters. In the TVP World account of the Wednesday briefing, Gawkowski described the theft as confirmed by MyDr itself. In a written statement quoted by Poland Daily 24, the same minister was more guarded: "At this stage of the investigation, it is not yet possible to conclusively confirm that a data breach occurred. However, there are many indications that an unauthorized person may have gained access to the data." MyDr's own August 12 cybersecurity update, as summarised by Undercode News, goes no further than confirming an incident affecting part of its systems, with incident response activated and external specialists, authorities and legal advisers engaged; the company says it has not yet established how the incident occurred, which systems were accessed, or whether personal data was exfiltrated. Read together, the picture is a live investigation in which ministerial confidence has run ahead of the victim's formal confirmation. Treat the 19 million figure as a claim corroborated by sampling, not as an audited count.
What lends the claim weight is the evidence handling described by ZTS and reported by Gazeta Lekarska. ZTS says that within the limits of what it could verify, it found no inconsistencies in the proof of intrusion supplied by the alleged perpetrators. That proof included a database screenshot for a prominent Polish politician showing a correct date of birth, PESEL, full name and two phone numbers (one independently confirmed), plus a list of 25 prescription numbers attributed to that person. The attackers also sent records for the ZTS journalist covering the story, whose PESEL and National Health Fund (NFZ) region were correct; the phone number field held "111111111," a placeholder commonly used by facilities that do not enter full contact details, which is itself a tell of genuine clinical data rather than fabrication.
Gawkowski said there are currently no indications that the theft was carried out by another state, and characterised it as the work of financially motivated cybercriminals.
What Was Taken
The claimed haul, by source:
- 18,814,422 unique PESEL numbers, per the attackers' own claim as relayed to ZTS and reported by both Gazeta Lekarska and Poland Daily 24. Gazeta Lekarska's headline rounds this to "over 18 million"; TVP World and UNN describe it as "almost 19 million" people, following the minister's phrasing. These are the same underlying claim expressed differently, not independent counts.
- Roughly 2TB of data, the volume carried in TVP World's own framing of the incident. No source in this set breaks that figure down by table or file type, and it should be read as an aggregate claim rather than a verified extraction size.
- Clinical and appointment data. Poland Daily 24 states MyDr stores appointment details and information about patients' health problems. The prescription-number list in the politician sample indicates prescription records are in scope.
- Corporate and internal data beyond patient records. Per Gazeta Lekarska, the attackers supplied screenshots from MyDr's Jira and HubSpot CRM instances purporting to show full access to internal tooling, a screenshot of an SMS sent to employees from MyDr's own SMSApi account, and a password-protected PDF addressed to the company's CEO containing internal correspondence, new-employee data, a whistleblower report, and a fragment of the database of doctors working with MyDr (consistent with public registers).
Two details deserve emphasis. First, the PESEL is not a revocable credential. It encodes date of birth and sex, is used across Polish public administration, banking and healthcare, and cannot be reissued the way a card number can. Second, the CEO's PDF was reportedly encrypted with his own PESEL as the password, and the extortion approach was framed as an "offer to purchase the results of a security audit." That is a deliberate humiliation ritual, and it signals an actor optimising for pressure rather than stealth.
Why It Matters
This is a supplier breach, not a hospital breach. One EMR vendor sits behind thousands of facilities, so a single compromise aggregates a patient population no individual clinic could ever assemble. Any organisation running a shared clinical platform should read the MyDr scope numbers as a description of its own blast radius.
The extortion posture is the second signal. Warsaw's public refusal to pay is the correct policy stance and removes the fiction that a quiet settlement suppresses a leak, but it also means defenders should plan for eventual publication or resale of the dataset rather than containment. Downstream, expect PESEL-driven identity fraud, credit applications, and targeted social engineering that quotes real prescription or appointment details to establish credibility. The minister's advice to citizens, securing the PESEL number through the government's mObywatel app, is a defensive lock against exactly that abuse and is worth mirroring in any customer guidance.
Context sharpens the picture. On August 7, days before the MyDr disclosure, researchers Robert Kruczek and Kamil Szczurowski presented findings at DEF CON from a sweep of Poland's public web: more than 10,000 affected public entities and 250,000 websites with security flaws, including airports, hospitals and government offices. They reported critical vulnerabilities in the Pad CMS content management system that gave passwordless access to over 300 public sites, unpatched because the software was declared end of life, and a separate bug reaching roughly 245 courts, about two-thirds of Poland's judiciary. TechCrunch notes some vendors treated the bug reports as inconveniences. That is the ecosystem MyDr operates in.
Regulatory exposure is real and precedented. Poland's DPA, the UODO, has already ruled on the shared-responsibility question in healthcare breaches: in case DKN.5131.12.2022, it reprimanded both a provincial specialist hospital and its external email provider after a hacked employee mailbox exposed names, addresses, phone numbers, vaccination appointments and national ID numbers of about 200 patients, finding GDPR violations including Article 28 controller-processor failings. MyDr is a processor for thousands of controllers. Every clinic using the platform inherits notification obligations under GDPR Articles 33 and 34, and the volume of health data here, a special category under Article 9, puts this several orders of magnitude beyond that precedent.
The Attack Technique
Unknown, and no source in this set establishes it. MyDr says it has not determined how the incident occurred or which systems were accessed. No ransomware family, affiliate brand or named group has been attributed.
What can be inferred from the evidence the attackers chose to publish is the depth of access, not the entry point. Simultaneous possession of clinical database contents, Jira, HubSpot CRM and the SMSApi sending account points to compromised identity rather than a single exploited web application, most plausibly credential theft or session hijack against an account with broad SaaS and administrative reach, followed by lateral movement across connected services. The Undercode summary makes the same structural point in general terms: applications, databases, cloud services, employee accounts, authentication systems, backups and third-party platforms are interconnected, and one foothold becomes a pathway.
One caution on attribution. Poland has been dealing with a wave of suspected Russian intrusions against energy and water providers, and CERT-UA has documented Sandworm subgroup UAC-0145 running fake job interviews against Ukrainian IT administrators since May as a route to admin credentials, per Risky Business. Those are regional context, not evidence about MyDr, and Gawkowski has said there is no current indication of state involvement here. Do not merge the threads.
What Organizations Should Do
- Inventory your EMR and clinical SaaS supply chain now. Identify every vendor holding patient records on your behalf, confirm each has a current Article 28 processing agreement, and demand written breach-notification timelines. The UODO precedent shows the regulator will pursue controller and processor alike.
- Enforce phishing-resistant MFA on administrative and SaaS-federated accounts. The MyDr evidence set spans a clinical database, Jira, a CRM and an SMS gateway. Prioritise the accounts that can reach several of those at once, and include third-party messaging and marketing platforms in scope, since they are routinely excluded from identity hardening.
- Instrument bulk-read detection on patient databases. Alert on volumetric query patterns, unusual export jobs and off-hours access by service accounts. An exfiltration on the claimed scale is loud in database telemetry and quiet in endpoint telemetry.
- Audit for end-of-life software in public-facing estates. The DEF CON research found unpatched, unsupported CMS deployments granting passwordless access to hundreds of Polish public sites. Enumerate what you run that no vendor supports, and treat "end of life" as an active vulnerability with an owner and a date, not a procurement footnote.
- Publish a vulnerability disclosure channel and staff it. The researchers cited a lack of reporting routes and bug bounties as a structural cause of Poland's exposure. A security.txt file and a monitored inbox cost nothing and convert hostile discovery into free reporting.
- Pre-write the extortion decision and the notification pack. Decide the no-payment position before an incident, not during one, and prepare GDPR Article 33 and 34 templates plus patient-facing guidance in advance. For Polish citizens specifically, that guidance should include locking the PESEL number via mObywatel.
- Rehearse the assumption that the data will be published. Where the leaked set includes national identifiers and clinical detail, plan for durable fraud and pretexting risk rather than a fixed remediation window, and brief staff that callers may quote genuine appointment and prescription details.
Sources: 'Unprecedented': Medical data of almost 19 million Poles ... | Security researchers scanned the Polish web and found courts, hospi... | MyDr Investigates Data Incident in Poland as Cybersecurity Concerns... | Hackers claim to have stolen data of nearly 19 million ... | A massive data breach in Poland affected nearly 19 million people УНН | Russian hackers adopt the fake job interview tactics | UODO (Poland) - DKN.5131.12.2022 - overview.legal | Wyciekły dane o ponad 18 mln polskich pacjentów - Gazeta Lekarska