SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-EZDROWIE-ME 2026-08-15

MyDr: Mass Health Record Theft and Extortion Attempt

"Polish government officials have confirmed a data breach at MyDr, an electronic medical records provider serving thousands of clinics nationwide, that may expose the personal and health data of close to 19 million…"

Polish government officials have confirmed a data breach at MyDr, an electronic medical records provider serving thousands of clinics nationwide, that may expose the personal and health data of close to 19 million people. Digital Affairs Minister and Deputy Prime Minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history" and said the company itself confirmed the theft of roughly 19 million records, while the attackers told a Polish security news outlet they hold 18,814,422 unique PESEL national identity numbers. Gawkowski stated there are currently no indications the theft was carried out by another state, and Prime Minister Donald Tusk described the motive as "purely criminal," pointing to a ransom demand. Note on sourcing: no primary victim notification, regulator filing, or national CERT advisory was available for this brief. Everything below is drawn from press reporting of government statements and should be treated as provisional.

What Happened

The chain of disclosure started outside government. Polish IT security news service Zaufana Trzecia Strona reported on Monday 11 August that it had been contacted on Saturday by people claiming responsibility for the intrusion, who said they had accessed the data of roughly 18.8 million people (per Notes From Poland and Poland Daily 24). Adam Haertle of Zaufana Trzecia Strona told reporters the attackers proved their access by supplying his own record from the database along with data on one of Poland's leading politicians (per thepublic.info, citing RMF24). Notes From Poland reports the same politician screenshot detail.

MyDr then acknowledged it had "become the target of an external, deliberate criminal activity involving some of our data." The Ministry of Digitalisation confirmed the attack publicly on Wednesday 12 August, and Gawkowski and Tusk held press conferences on 13 August.

Accounts of how firm the confirmation was differ by date, and the difference is worth noting rather than smoothing over. Poland Daily 24 quotes Gawkowski saying that at that stage "it is not yet possible to conclusively confirm that a data breach occurred," though there were "many indications that an unauthorized person may have gained access." By 13 August, per Anadolu Agency, his language had hardened: "As confirmed by the company itself, 19 million records were stolen." Read as a sequence, that is an early cautious statement followed by company-confirmed loss, not a contradiction, but the confirmed scope may still move.

Pollar reports that Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office, said the perpetrator gained unauthorised access to MyDr's servers no later than 6 August 2026 by breaking or circumventing IT security measures, with first investigative actions taken ex officio on 11 August and the Central Bureau for Combating Cybercrime (CBZC) formally opening its investigation on 12 August. The offence as charged carries up to three years in prison.

What Was Taken

Figures vary by source and by who is doing the claiming, so both the government-side and attacker-side numbers are given here.

Record counts: the attackers claim 18,814,422 unique PESEL numbers (Zaufana Trzecia Strona, as reported by Poland Daily 24, thepublic.info and techtiper). Gawkowski put the company-confirmed figure at approximately 19 million records (Anadolu Agency, Brandsit). Most outlets round to "nearly 19 million people affected."

Data volume: the Ministry and most reporting put the stolen database at over 2 TB (Brandsit, Pollar, thepublic.info, DistantNews citing Rzeczpospolita). Techtiper reports the attackers themselves claimed up to 2.5 TB. The 2 TB figure is the one attached to official statements; 2.5 TB is an attacker claim only.

Data types reported across sources: first and last name, PESEL national identity number, date of birth, telephone numbers, email addresses, doctors' visit notes, prescription information, and medical conditions or health histories (Pollar, thepublic.info, DistantNews).

Blast radius: MyDr's system was used by around 12,000 healthcare facilities (Brandsit, Pollar) and, per techtiper, the company reportedly works with 47,000 doctors, against roughly 220,000 physicians and dentists licensed in Poland as of 30 June 2026. Brandsit and techtiper both note the platform handles about 3 million appointments and 2.7 million prescriptions per month. Brandsit makes an important scoping point: because MyDr is the technical backbone behind clinics rather than a consumer brand, many patients may be in the database without ever having heard of the company.

One containment note that matters for readers assessing exposure: MyDr has been part of the Docplanner group since 2023, alongside the ZnanyLekarz platform, but Brandsit reports (citing information given to CRN) that the two systems are separate and do not exchange data, so this is not a ZnanyLekarz breach.

As of the latest reporting, Haertle said the attackers had not published the database. That is a temporary state, not a resolution.

Why It Matters

This is a supplier compromise, not a hospital compromise. One vendor sitting underneath 12,000 facilities converts a single intrusion into a national-scale exposure, and no individual clinic's own security posture would have prevented it. Any organisation that has consolidated sensitive records behind a single EMR, billing, or scheduling vendor should read this as a direct analogue.

The data mix is unusually damaging. PESEL numbers plus date of birth plus phone number is an identity-fraud kit; adding diagnoses and prescriptions makes phishing and social engineering far more convincing, because an attacker who can name your medication is credible in a way a generic lure is not. Brandsit flags exactly this combination as the follow-on risk.

There is a targeted-coercion dimension too. Haertle warned that medical information on senior politicians creates blackmail leverage, and the attackers deliberately used a politician's record as proof of access. Gawkowski's public position was blunt: "Nobody will negotiate with anyone. Nobody will give in to any blackmail."

Finally, the response itself faltered under load. DistantNews, citing Rzeczpospolita, reports that the government's Bezpieczne Dane checking site (bezpiecznedane.gov.pl) was inaccessible, likely due to traffic volume, at the moment citizens were being directed to it. Breach-notification infrastructure that collapses at national scale is a planning failure worth copying into your own incident runbook.

Brandsit notes cybersecurity incidents reported in Poland rose 144 percent year on year in 2025, which is the backdrop this lands against.

The Attack Technique

Little is confirmed, and the sources do not support a specific intrusion vector.

What is on the record: the prosecutor's office says access to MyDr servers was obtained no later than 6 August 2026 by "breaking or circumventing IT security measures" (Pollar), which is charging language rather than a technical finding. Tusk characterised the operation as involving "very sophisticated techniques and methods" and assessed the motive as extortion. Gawkowski said cybersecurity services were still working to establish how the incident occurred, and that affected systems are now secure and operating normally (DistantNews).

No malware family, initial access vector, exploited CVE, or named threat group has been published. The perpetrators remain unidentified. Their choice to contact a journalist rather than post to a leak site, and to withhold publication while a ransom demand is outstanding, fits a data-extortion crew building pressure rather than a hacktivist or espionage pattern. That is an inference from behaviour, not an attribution.

What Organizations Should Do

  1. Inventory your data processors, not just your systems. Identify every third party that holds patient, customer, or identity data on your behalf, what fields they hold, and how many records. Brandsit's core lesson is that concentration risk sits with the vendor, and most organisations cannot currently answer this question quickly.
  2. Contractually require breach telemetry from suppliers. Demand defined notification windows, access logging you can request, and evidence of segmentation between the vendor's product lines. Docplanner's separation of MyDr from ZnanyLekarz is what limited this to one dataset.
  3. Rehearse notification at full scale. Load-test your public checking or notification endpoint against your entire affected population, plus a large margin. The Bezpieczne Dane outage shows what happens when you do not.
  4. Prepare for medically-informed phishing. Brief staff and, where relevant, customers that attackers now have diagnosis and prescription details and will use them for credibility. Update fraud-detection rules and helpdesk identity-verification scripts, since knowledge-based verification using personal details is now weaker.
  5. Confirm your regulatory obligations flow both ways. Poland's data protection authority (UODO) reminded controllers who used MyDr that the notification duty is theirs, not only the processor's. If your vendor is breached, you likely still owe notifications.
  6. Advise affected individuals on identity locks. In Poland the practical step is reserving or locking the PESEL number via the mObywatel app or a local office (Notes From Poland, DistantNews). Equivalent controls exist in other jurisdictions as credit freezes or identity locks. Build the instruction into your notification templates in advance.
  7. Hunt backwards past your assumed start date. Access here predated discovery by at least several days and possibly longer. Set your log retention and threat-hunting window wider than the earliest confirmed intrusion date.

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Poland hit by theft of 19 million patients’ data from medical platf... | The MyDr data breach may affect 19 million Poles. The data came fro... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | Hackers claim to have stolen data of nearly 19 million Polish patients | Cyberattack in Poland: data breach affecting nearly 19 million citi... | Data of 18 Million Poles in Hackers' Hands? Experts and Services In... | Data Leak Exposes 19 Million Poles; Government Website Fails Dista...