Poland's Ministry of Digital Affairs confirmed on 12 August 2026 that MyDr sp. z o.o., a private vendor of electronic medical records and practice-management software, was breached by attackers who exfiltrated patient data at national scale. Deputy Prime Minister and digital affairs minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history." Figures in circulation do not agree: the attackers told Polish security outlet Zaufana Trzecia Strona they hold 18,814,422 unique PESEL numbers and roughly 2.5 TB of data (StartupKit); the government put the total at "nearly 19 million" records (Notes from Poland, Anadolu Agency, Pollar); Pollar reports the stolen database "exceeds 2 TB." MyDr itself has confirmed no count at all. Against a Polish population of roughly 37 million, the government figure implies about half the country. Prime Minister Donald Tusk, speaking on 13 August, described the tradecraft as sophisticated and the motive as "purely criminal," pointing to an attempted ransom extortion against the company.
What Happened
MyDr supplies records software to healthcare providers across Poland. Pollar puts the customer base at 12,000 facilities; Notes from Poland describes it more loosely as "thousands of medical facilities." The company was acquired by the Docplanner (ZnanyLekarz) group, announced 9 January 2023, according to StartupKit.
Per prosecutor Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office, the perpetrator gained unauthorised access to MyDr's servers no later than 6 August 2026 by breaking or circumventing IT security measures. The offence as charged carries up to three years' imprisonment.
The attackers then went to the press rather than staying quiet. Notes from Poland reports that Zaufana Trzecia Strona was contacted by the alleged perpetrators on Saturday and published first at the start of the following week; Pollar's timeline dates the first ex officio investigative actions to 11 August. The two accounts differ by a day on exactly when the story broke, but agree on sequence: attacker contact, journalist verification, then official confirmation. Z3S said the attackers also supplied a screenshot from the compromised database showing the personal data of "one of the most important politicians in Poland," a classic leverage play in an extortion negotiation.
MyDr responded with a statement that it had "become the target of an external, deliberate criminal activity involving some of our data." The Ministry of Digitalization confirmed the attack on 12 August and Poland's Central Bureau for Combating Cybercrime (CBZC) formally opened an investigation the same day. Tusk and Gawkowski held press conferences on 13 August.
There is a live contradiction between two authoritative accounts. StartupKit notes that Gawkowski said on 12 August that nearly 19 million records were stolen, "which the company itself confirms" (citing Bankier), while MyDr's own incident page, updated at 18:35 CET the same day, states it cannot confirm the quantity or type of data disclosed. That is a government primary source and a victim primary source published hours apart, disagreeing on the central fact. Treat the 19 million figure as the government's number, not a company-verified one.
What Was Taken
Per the Ministry of Digitalization as reported by Pollar, the stolen set includes names, PESEL national identification numbers, phone numbers, email addresses, doctors' visit notes, and prescription information. Notes from Poland similarly describes patients' personal information plus medical details including diagnoses and prescriptions.
Volume claims, stated as a range:
- Attackers' claim: 18,814,422 unique PESEL numbers, roughly 2.5 TB (via Zaufana Trzecia Strona, reported by StartupKit). Z3S said it could verify neither figure, though it did verify part of the sample.
- Government figure: nearly 19 million records (Gawkowski, via Notes from Poland, Pollar and Anadolu Agency).
- Database size per Pollar: in excess of 2 TB.
- MyDr's own position: no confirmed count or data type, with the affected data described as "most likely historical, from 2024 and earlier years" (StartupKit, citing MyDr's incident page).
The "historical" characterisation is the company's, and it does not reduce the exposure much. A PESEL number does not expire and neither does a diagnosis. Free-text visit notes and prescription records are among the most sensitive categories in any European dataset, and unlike a password they cannot be rotated.
Why It Matters
Three things make this incident structurally worse than its headline number.
The vendor is the blast radius. No individual clinic was breached. One software supplier sitting behind thousands of practices was, and the aggregation did the rest. This is the same pattern visible elsewhere in Poland this month: The Record reported that convenience chain Żabka, with more than 12,800 stores, was breached through a compromised account belonging to an external service provider rather than through its own infrastructure. Different sector, different attacker, same lesson about who actually holds your keys.
Identity fraud exposure is durable and national. Gawkowski urged citizens to check government services to see whether their data is affected and to "lock" their PESEL number against fraudulent credit applications. That advice is a tacit admission that remediation now falls on 19 million individuals, not on one company.
Poland is under sustained, varied pressure. Separately from this breach, CERT Polska disclosed at DEF CON 34 that the 29 December cyberattack on a Polish combined heat and power plant was the first observed case of attackers reaching an OT network through a private APN, a dedicated mobile network operated with a carrier by the local distribution system operator. Infosecurity Magazine ties that activity to Russian-linked actors. Help Net Security reports the plant serves heat to around 50,000 residents; the attack shut down a steam turbine and the water treatment system, and it occurred the same day as coordinated attacks affecting 30 renewable energy facilities and another CHP plant. The MyDr breach appears criminal and financially motivated by the government's own reading, but it lands on a national defender community already stretched across state-aligned intrusions into critical infrastructure.
The Attack Technique
Initial access has not been disclosed. What is on record: the prosecutor states the intruder broke or circumvented IT security measures to reach MyDr's servers no later than 6 August 2026; Tusk described "very sophisticated techniques and methods"; and the apparent objective was ransom extortion. No threat actor has been named or attributed by any source, and no ransomware deployment has been reported. There is no vendor advisory naming an exploited CVE, no indication of whether the entry point was credential compromise, an internet-facing application flaw, or a supplier account. Anyone claiming a specific initial access vector today is ahead of the evidence.
One structural weakness is documented. StartupKit argues MyDr had no supported external channel for reporting a security flaw, which is why the attackers' outreach landed in a journalist's inbox instead of a security team's. That is a single OTHER-tier analysis and an argument about disclosure speed, not root cause; the same piece concedes a vulnerability disclosure program would not have prevented the breach. It is still worth noting that the first credible detail about this incident reached the public through a news site rather than through the vendor.
For the OT case reported by CERT Polska, the technique is documented in detail and is worth reading separately: Help Net Security notes that analysis took over three months, that staff initially attributed the disruption to contractor error during scheduled maintenance, and that the hunt involved forgotten remote access devices, wiped industrial hardware and infrastructure assumed to be isolated.
What Organizations Should Do
- Inventory which suppliers hold your customer or patient data, and at what aggregation. The question is not "is this vendor secure" but "how many of my records sit in one place next to everyone else's." A records platform serving 12,000 facilities is a national-scale target regardless of any single customer's controls.
- Enforce identity controls on third-party and contractor accounts specifically. Phishing-resistant MFA, per-vendor scoped credentials, time-bounded access, and separate monitoring for supplier identities. Both this incident and the Żabka intrusion reported by The Record point at the supplier boundary.
- Build detection for bulk read and egress, not just for intrusion. Multi-terabyte exfiltration from a records database should generate an alert on volume and query pattern alone. Assume the perimeter alert will not fire.
- Publish a vulnerability disclosure channel and staff it. A security.txt file and a monitored inbox cost almost nothing and change who reaches you first when someone outside finds a problem.
- Rehearse the extortion-plus-media scenario. In this case the attackers contacted a journalist, leaked a politician's record as leverage, and forced the company to respond publicly within days. Have legal, comms, the regulator notification path, and law enforcement engagement pre-wired before you need them.
- Do not let "historical data" downgrade your severity rating. National ID numbers, diagnoses and prescriptions from 2024 and earlier carry the same fraud and coercion value today as fresh records.
- For operators of industrial estates: treat private APNs and other "isolated" links as in-scope. CERT Polska's findings show that assumed-isolated cellular paths and forgotten remote access devices were the route, and that the first symptom looked exactly like ordinary human error.
Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Polish convenience store chain Żabka hacked through third-party acc... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | Hackers Cross From IT to OT Through a Private APN in Poland | Poland hit by theft of 19 million patients’ data from medical platf... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | MyDr Breach: Five Leaks, One Missing Disclosure Channel StartupKit