Poland's Ministry of Digitalization confirmed on Wednesday 12 August 2026 that a cyberattack on MyDr, a private supplier of electronic medical records software, resulted in the theft of personal and health data belonging to nearly 19 million citizens. Pollar reports the ministry's confirmation and puts the stolen database at more than 2 TB; Poland Daily 24, citing the Polish security site Zaufana Trzecia Strona, reports the attackers themselves claim a precise figure of 18,814,422 unique PESEL national identification numbers. Anadolu Agency headlines the incident as affecting "nearly 19 million" Poles. Prime Minister Donald Tusk described the intrusion at a Thursday press conference as using "very sophisticated techniques and methods" with a motive that "appears to be purely criminal," pointing to an attempted ransom extortion against the company. All three accounts of the medical breach available here are lower-tier reporting rather than a MyDr statement or a regulator filing, and the figures below should be read with that in mind.
What Happened
MyDr supplies electronic medical records software to Polish healthcare providers. Pollar puts its footprint at 12,000 healthcare facilities nationwide; Poland Daily 24 describes it more loosely as "thousands" of facilities and notes it belongs to the same corporate group as the well known ZnanyLekarz appointment platform. The company is characterised across reporting as one of Poland's largest EMR providers, which is what turns a single vendor compromise into a national-scale event.
According to Pollar, prosecutor Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office overseeing the case, stated that the perpetrator gained unauthorized access to MyDr's servers no later than 6 August 2026 by breaking or circumventing IT security measures. The published timeline runs: intrusion on or before 6 August; first investigative actions taken ex officio on Monday 11 August; ministry confirmation and the formal launch of a CBZC (Central Bureau for Combating Cybercrime) investigation on 12 August; press conferences by Tusk and Digital Affairs Minister Krzysztof Gawkowski on 13 August. A portion of the stolen data was sent to the editorial team at Zaufana Trzecia Strona, which is how the incident surfaced publicly.
Accounts of confirmation status shifted over 48 hours and that shift is worth stating plainly. Poland Daily 24 quotes Gawkowski saying that "at this stage of the investigation, it is not yet possible to conclusively confirm that a data breach occurred," while acknowledging "many indications that an unauthorized person may have gained access to the data." Pollar's later reporting has the Ministry of Digitalization confirming the theft outright on 12 August. The likeliest reading is that government posture hardened as evidence came in, not that the two statements describe different events, but no MyDr statement quantifying the loss appears in the sourcing reviewed here.
What Was Taken
Pollar reports the stolen database exceeds 2 TB and contains names, PESEL identification numbers, phone numbers, email addresses, doctors' visit notes and prescription information. Poland Daily 24 adds that MyDr stores details about medical appointments and health problems.
That combination is close to a worst case. PESEL is Poland's permanent national identifier and cannot be rotated the way a password or card number can. Pairing it with a verified name, phone number and email address produces a durable, high-confidence identity record. Adding clinician visit notes and prescription histories layers on health information that supports targeted extortion, insurance and benefits fraud, and highly credible social engineering against both patients and their providers.
On volume, the sources are close but not identical. The attackers' own claim of 18,814,422 unique PESEL numbers is a seller's assertion relayed through a journalist, not a verified count; the ministry's "nearly 19 million citizens" is consistent with it but not independent corroboration of the exact figure. If the upper figure holds, it covers roughly half the Polish population.
Why It Matters
This is a supplier compromise with sovereign-scale consequences. No hospital or clinic was breached directly. One software vendor sitting underneath thousands of healthcare facilities was, and the aggregated data flowed out through it. Healthcare IT consolidation has quietly created a small number of vendors whose single failure exceeds the blast radius of any individual provider they serve.
It also lands in the middle of a sustained run of pressure on Polish infrastructure. The Record reports that Poland's largest convenience store chain, Żabka, confirmed on 4 August that attackers reached technical systems used to communicate with its franchise network through an account belonging to an external service provider, not through Żabka's own infrastructure; the data was subsequently advertised on a cybercrime forum for €5,000. Ransomnews reports the seller claimed roughly 541,000 Jira tickets and source code from 89 GitLab repositories, figures Żabka has not confirmed, and says its own review of the sample archive found the checkable counts held up while containing no consumer records, loyalty data or payment card data. Separately, CERT Polska has disclosed that a 29 December cyberattack on a combined heat and power plant serving around 50,000 residents was, per Help Net Security and Security Affairs, the first observed case of attackers reaching an OT network through a private APN, a dedicated mobile network set up between a distribution system operator and a mobile carrier. Infosecurity Magazine attributes that activity to Russian-linked actors, citing CERT.PL.
These are separate incidents with different actors and different motives. The pattern that connects them is structural: retail, energy and healthcare in Poland are all being reached through the seams between organisations rather than through their front doors.
The Attack Technique
The specific intrusion method at MyDr has not been published. What is on the record is the prosecutor's legal characterisation, that access was obtained by breaking or circumventing IT security measures, an offence carrying up to three years' imprisonment, and Tusk's description of "very sophisticated techniques and methods." Treat the sophistication claim as a political assessment delivered before an investigation concluded, not as technical attribution. No threat actor has been named and no ransomware brand has claimed the incident.
The behavioural signal is more useful than the missing tradecraft. The attackers exfiltrated at scale, contacted a security journalist with samples, and, per Tusk, sought a ransom from the company. That is the double-extortion playbook without a required encryption stage: leverage comes from the threat of publication, and media contact is used to manufacture urgency and prove possession.
For contrast, the two adjacent Polish cases have documented entry vectors. Żabka's was a compromised external service provider account. The CHP plant's was a private APN assumed to be isolated, an assumption CERT Polska's Marcin Dudek described at DEF CON 34 as unwinding through "false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated." Notably, plant staff initially attributed the turbine and water treatment shutdown to contractor error during scheduled maintenance, and reported it only for information; CERT Polska pursued a cyberattack hypothesis anyway and spent more than three months confirming it.
What Organizations Should Do
- Inventory which suppliers hold your aggregated data, not just which ones you have contracts with. A single EMR, billing or scheduling vendor can concentrate more identity data than your own estate. Rank third parties by data volume held, not by contract value or by how they scored on a questionnaire.
- Instrument for bulk egress at the vendor boundary. A 2 TB extraction is not subtle. Alert on volumetric anomalies in database reads and outbound transfers from supplier-facing systems, and set thresholds against normal daily baselines rather than fixed limits nobody revisits.
- Treat every external service provider account as privileged. Both the MyDr and Żabka cases point at the supplier seam. Enforce phishing-resistant MFA, scope contractor access to named systems, time-box it, and audit for standing accounts nobody has reviewed since onboarding.
- Assume national identifiers are permanently compromised for affected populations. Where PESEL, or its equivalent in your jurisdiction, is used as a knowledge-based authenticator in call centres or account recovery, remove it from that role now. It is a lookup key, not a secret.
- Rehearse the extortion-without-encryption scenario. Build the playbook for the case where nothing is encrypted, data is already gone, a journalist has samples, and a ransom demand arrives. Decide in advance who speaks to the regulator, to law enforcement and to the press, and on what timeline.
- Do not dismiss anomalies that have a convenient mundane explanation. The Polish CHP plant was nearly written off as contractor error during maintenance. Where an incident coincides with planned work, verify the benign explanation instead of assuming it.
- Extend OT threat modelling to carrier-provided connectivity. Private APNs, cellular backhaul and DSO-managed links are frequently recorded as isolated in architecture documents and are not. Validate the isolation claim empirically.
Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Polish convenience store chain Żabka hacked through third-party acc... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | Hackers Cross From IT to OT Through a Private APN in Poland | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | Hackers claim to have stolen data of nearly 19 million Polish patients | Żabka alleged data leak: 541k Jira tickets, 89 repos Ransomnews