SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-GOVERNMENT- 2026-08-19

MyDr: 19 Million Polish Patient Records Exposed in a Two Year Detection Gap

"Polish authorities are investigating a breach of MyDr, a privately owned Polish healthcare software provider, that the government says may cover the personal and medical data of nearly 19 million people and more than…"

Polish authorities are investigating a breach of MyDr, a privately owned Polish healthcare software provider, that the government says may cover the personal and medical data of nearly 19 million people and more than 12,000 medical facilities. Digital affairs minister and Deputy Prime Minister Krzysztof Gawkowski called it "an extraordinary and very large incident in terms of the security of Poland's information sphere" and, at a subsequent briefing, "one of the largest incidents in Poland's history." The attackers themselves put the figure at 18,814,422 unique national identification numbers when they contacted Polish security news service Zaufana Trzecia Strona on 8 August 2026. Accounts differ sharply on one central question: how long the data had been exposed before anyone in government noticed.

What Happened

The public timeline starts outside government. Zaufana Trzecia Strona reported on 10 August 2026 that it had been contacted two days earlier by people claiming to have accessed the records of roughly 18.8 million Poles. The claimants supplied a screenshot from the compromised database showing the personal data of what the outlet described as "one of the most important politicians in Poland," a detail reported consistently by both Brussels Signal and Notes From Poland.

MyDr then confirmed it had "become the target of an external, deliberate criminal activity involving some of our data." By the end of that week the company said it had identified and removed the cause of the incident and introduced additional security measures. It has not disclosed the vulnerability or how the attackers gained access. MyDr also said it had found no evidence, as of its updates, that the affected data had been published or otherwise made publicly available.

On 12 August, Gawkowski publicly acknowledged the leak. This is where the accounts diverge. Brussels Signal reports that Gawkowski characterised the leak as having occurred "in recent days," while deputy digital affairs minister Michał Gramatyka said he had no knowledge of a leak of medical data affecting nearly 19 million Poles that had occurred as far back as two and a half years earlier. That two year detection gap is the framing Brussels Signal, a single OTHER tier source, puts on the incident, and it should be read as that outlet's characterisation rather than a settled fact.

The Record, reporting the official line, gives a materially different shape: Polish authorities said the attackers obtained unauthorised access to historical data held in MyDr systems through April 2024, and that the exposure may not involve all MyDr customers or their patients. Those two statements are not necessarily contradictory. Data can have a cut off date of April 2024 without the intrusion itself dating to 2024. But no source in this set resolves whether the access was recent and reached back into an old archive, or whether the intruders had been inside for years. Treat dwell time as unestablished.

Warsaw district prosecutors have opened an investigation. Brussels Signal notes the offence under examination falls under Article 267 of the Polish penal code, carrying a maximum sentence of two years.

What Was Taken

Figures vary by source and by who is speaking:

The government's "nearly 19 million" replaced MyDr's earlier hedged position that it could not yet say what had been taken. For scale, Poland's population is roughly 37 million, so the claimed record count covers around half the country.

Content is the aggravating factor here. Notes From Poland reports the data includes patients' personal information alongside medical details such as diagnoses and prescriptions. Gawkowski urged Poles to check government services for exposure and to "block" their PESEL national identity number to prevent fraud, which is the standard Polish remedy against identity based credit fraud and indicates the government assessed the identity data as directly abusable.

Attribution remains open. No actor has been identified. Per CTI Pilot, Gawkowski said there is no indication of an attack from Russia or another state and that cybercriminals are "very likely" responsible. That framing is notable for a country whose public sector is a standing target for state linked operations, and it is a government assessment rather than a published technical finding.

Why It Matters

Three things make this brief worth more than its record count.

The processor gap. MyDr is a data processor. The controllers under GDPR are the roughly 12,000 individual healthcare facilities that use its software. CTI Pilot reports the Polish regulator confirmed the breach notification duty sits with those clinics, not with the platform. The practical consequence is that there is no single entity that can notify 19 million people. Notification is fragmented across thousands of small organisations, most of which have no breach response capability. This is a structural failure mode for every multi tenant healthcare, HR, and payroll SaaS platform in Europe, and it is the part of this incident most likely to repeat elsewhere.

Systemic connectivity. MyDr's software connects healthcare providers to P1, Poland's nationwide electronic health platform underpinning e-prescriptions and referrals. A compromise of a connector into a national health backbone is a different risk class than a compromise of a clinic. Poland's e-Health Center responded by replacing the digital certificates that medical systems use to connect to P1, a precautionary move. Gawkowski said authorities found no evidence the certificates were stolen or misused; the replacement is intended to prevent later abuse of anything that might have been silently compromised. Health Minister Jolanta Sobierańska-Grenda said the incident did not pose a threat to public health services, and officials said certificate rotation should not disrupt e-prescriptions or referrals.

The detection question. Whether or not the two and a half year figure holds, a deputy minister publicly stating he had no knowledge of an incident of this scale points to a visibility problem between a private processor, its thousands of controller customers, and the national authorities meant to oversee them. The first credible signal reaching the public came from the attackers contacting a journalist.

The Attack Technique

For MyDr, this is the honest answer: unknown. The company has not disclosed the initial access vector, the vulnerability, or the intrusion method, saying only that it identified and removed the cause. Authorities have described the outcome, unauthorised access to historical data through April 2024, but not the mechanism. Anyone publishing a specific MyDr TTP right now is guessing.

What is worth setting alongside it is a separate and unrelated Polish incident disclosed in the same window, because it shows the operating environment Polish defenders are working in. CERT Polska published a follow up report over the weekend of 8 to 9 August 2026 detailing a second attack on the country's energy sector, conducted in parallel with the December 2025 campaign against roughly 30 wind and solar installations and a large CHP plant. The second target was a smaller combined heat and power plant supplying heat to around 50,000 residents.

The novel element was the entry path. Per CERT Polska as reported by BleepingComputer, Help Net Security, SecurityWeek, and Infosecurity Magazine, the intrusion began at an internet exposed FortiGate VPN and firewall at a wind farm, pivoted through a Teltonika cellular router on that network, and reached the plant's OT environment via a private Access Point Name, a dedicated mobile network set up between the distribution system operator and a mobile carrier. CERT Polska attributes the success in part to "a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another," and describes this as the first observed case of a private APN being used as an OT attack vector, warning the same configuration is common in Poland and internationally. The attackers switched off PLCs and password protected access, shutting down a steam turbine and the process water treatment system. Staff restored operations quickly and heat and power supply to customers were not interrupted.

Attribution for the energy attacks varies by outlet. BleepingComputer names the Russian linked Electrum group; SecurityWeek attributes it to Sandworm. Help Net Security notes maintenance work was underway that day, so staff initially assumed contractor error and reported it only informationally; CERT Polska investigated anyway, and analysis took over three months, which is why it was excluded from the initial report. CERT Polska head Marcin Dudek presented the findings at DEF CON 34.

These are two distinct incidents with no reported connection. The energy attacks are assessed as state linked and destructive; the MyDr breach is currently assessed by the Polish government as criminal and data theft driven.

What Organizations Should Do

  1. Map your processor relationships and who owes notification. If you are a controller relying on a shared platform, confirm in writing who notifies data subjects and the supervisory authority when that platform is breached. The MyDr case shows this obligation can land on thousands of small organisations that have never planned for it. Build the notification template now, not during the incident.
  2. Demand incident telemetry from your SaaS processors, not just an SLA. Contractually require breach notification windows, access log retention, and the right to receive indicators. MyDr's customers learned the scope from a press conference.
  3. Rotate machine identities on a defined trigger, not on suspicion of theft. Poland's e-Health Center replaced P1 connection certificates with no evidence they were stolen. Treat certificates, API keys, and service account credentials held by a breached vendor as compromised by default and have a tested rotation runbook that does not require downtime.
  4. Audit private APN and cellular backhaul segmentation. CERT Polska's finding that devices inside a private APN could freely reach each other is a configuration many operators assume is isolated by the carrier. Verify client isolation with the carrier, apply explicit ACLs between APN endpoints, and inventory every cellular router, including forgotten remote access devices.
  5. Patch and monitor internet facing edge appliances. Both Polish incidents in this window ran through infrastructure the defenders were not watching closely. FortiGate and similar VPN or firewall devices at remote or unstaffed sites need the same patch cadence and log forwarding as core assets.
  6. Treat "probable engineering error" as a hypothesis, not a conclusion. The smaller CHP plant reported its outage for information only because maintenance was underway. CERT Polska investigated anyway and found an intrusion. Build a low friction path for operations staff to escalate anomalies that already have a plausible benign explanation.
  7. For affected Poles specifically: check exposure through government services and block your PESEL number, as the digital affairs ministry advised. Expect health themed phishing and identity fraud attempts referencing plausible medical detail.

Sources: Tusk government unaware for two years of data breach - Brussels Signal | Poland probes MyDr healthcare software breach potentially affecting... | Hackers breached a small Polish energy plant via private APN last year | Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy F... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | Poland hit by theft of 19 million patients’ data from medical platf... | UPDATE — Poland's government puts the MyDr breach at nearly 19 mill...