Polish electronic medical documentation vendor MyDr has been breached in an intrusion that Polish government officials estimate touched nearly 19 million people, roughly half the national population, across more than 12,000 healthcare facilities. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski called it "an extraordinary and very large incident in terms of the security of Poland's information sphere" and, per the ctipilot brief, "one of the largest incidents in Poland's history." Prime Minister Donald Tusk said the attack appears financially motivated and consistent with a ransom extortion attempt. Note on sourcing: none of the available material is a primary victim notification, regulator filing, or CERT advisory on this incident. MyDr's own statements reach us only as quotations inside outlet reporting, and the sharpest claim in the set, that the leak went undiscovered for two years, rests on a single OTHER-tier source.
What Happened
The incident surfaced publicly on August 10, 2026, when Polish IT security news service Zaufana Trzecia Strona reported that it had been contacted on August 8 by people claiming to be the perpetrators (per Brussels Signal). The claimants said they had accessed data on roughly 18.8 million people, giving a precise figure of 18,814,422 unique identification numbers, and backed the claim by sending the outlet a screenshot from the compromised database showing personal data belonging to what Brussels Signal describes as "one of the most important politicians in Poland."
Two days later, on August 12, Gawkowski publicly confirmed the leak and the government opened its investigation. MyDr said parts of its systems had been affected by "external, intentional criminal activity," and by the following Friday said it had identified and removed the cause and introduced additional security measures (The Record). The company did not disclose the vulnerability or the access path.
Warsaw district prosecutors and Poland's Central Bureau for Combating Cybercrime (CBZC) are investigating unauthorized access under Article 267 of the Polish penal code, an offence carrying up to two years' imprisonment. Poland's domestic intelligence service ABW has contacted prominent public figures whose data was affected, specifically to reduce blackmail exposure (TVP World).
Conflicting Accounts on Timeline
The sources do not agree on when this started, and the disagreement is the single most important open question in the incident.
- Recent intrusion. GovInfoSecurity reports that attackers appeared to have gained access to MyDr's IT environment "no later than Aug. 6," 2026. TVP World says the breach "took place on Wednesday," consistent with an August 2026 event. Gawkowski, on August 12, said the leak occurred in recent days (Brussels Signal).
- Historical data. MyDr's own statement, quoted by GovInfoSecurity, says "the data involved in the incident is likely historical, dating back to 2024 and earlier." The Record reports authorities saying the hackers obtained access to historical data held in MyDr systems through April 2024, and that it may not cover all MyDr customers or their patients.
- Two years undetected. Brussels Signal reports that deputy digital affairs minister Michał Gramatyka said he had no knowledge of a leak of medical data on nearly 19 million Poles that occurred "as far back as two and a half years ago," and frames the government as unaware for two years.
Read together, the most defensible reading is that a 2026 intrusion exfiltrated a historical dataset whose contents stop around April 2024. The "two years undiscovered" framing is carried by one OTHER-tier outlet and appears to rest on the age of the data rather than on any confirmed dwell time. Treat it as an unresolved claim, not a confirmed dwell-time finding, unless CERT Polska or the regulator establishes an earlier compromise date. Defenders should also hold open the less comfortable possibility Gramatyka's remark implies: that a separate, earlier exposure of the same dataset went unnoticed, which is what "they leak twice" in the Brussels Signal headline gestures at.
What Was Taken
Volume figures differ and should be quoted as a range: GovInfoSecurity describes an "alleged 2.5 terabyte data theft," while the ctipilot brief cites Gawkowski (via Gazeta Prawna, August 13) saying the stolen database "exceeds 2 TB." Population figures are more consistent: the government estimate is "nearly 19 million" people, while the claimed perpetrators put it at 18,814,422 unique identifiers. More than 12,000 medical facilities use MyDr services, per the digital affairs ministry.
Content-wise, the exposure covers PESEL numbers, Poland's lifetime national identifier. GovInfoSecurity draws the comparison to a US Social Security number while noting the PESEL is used far more broadly, including for routine transactions such as rentals and utilities. TVP World reports that prescription, medication and other sensitive patient data were included. That combination, a permanent national identifier bound to clinical history, is close to the worst-case content profile for a healthcare data set: the identifier cannot be rotated and the medical detail carries indefinite blackmail value.
As of the most recent reporting, Gawkowski said the stolen records had not appeared in the public domain or been offered for sale, and MyDr said it had found no evidence the affected data had been published or otherwise made publicly available. Gawkowski acknowledged there is no guarantee the records will not eventually leak.
Why It Matters
Three points deserve defender attention beyond the raw scale.
The notification gap is structural, not administrative. Per the ctipilot brief, the regulator has confirmed that because MyDr is a processor rather than a controller, the GDPR notification duty sits with the roughly 12,000 individual clinics that are the controllers, not with the platform. There is no central mechanism to tell 19 million people what happened to their records. Expect notification to arrive unevenly, late, or not at all across thousands of small practices, and expect that vacuum to be filled by phishing that impersonates official notice.
Attribution is being framed away from the state actor default. Gawkowski said there is no indication of an attack from Russia or another state and that cybercriminals are "very likely" responsible; Tusk said "the motivation appears to be purely criminal. There are many indications that this was an attempt to extort a ransom," while describing the methods as "very sophisticated." That is a notable framing given the wider threat picture. Separate CERT Polska reporting covered by BleepingComputer, Infosecurity Magazine and Help Net Security details a December 29, 2025 destructive campaign against Polish energy infrastructure attributed to the Russia-linked Electrum group, which hit 30 wind and solar installations plus two combined heat and power plants. Those energy intrusions are a distinct incident from the MyDr breach with no reported connection; the relevance is that Poland is defending criminal extortion and state-linked destructive operations concurrently, and misclassifying one as the other misallocates response.
Supply chain concentration in health IT is a national-scale single point of failure. MyDr's software connects healthcare providers to P1, Poland's nationwide electronic health platform underpinning e-prescriptions and referrals. One vendor compromise put roughly half a country's population at risk.
The Attack Technique
The specific intrusion vector has not been disclosed. MyDr said it identified and removed the cause and added security measures but gave no detail on the vulnerability or how attackers gained access (The Record). Gawkowski said the vulnerability exploited by the hackers has since been identified and patched (TVP World). CBZC characterises the case as an unidentified person obtaining unauthorized access over the internet to all or part of MyDr's systems.
What is known about the operation: access was achieved no later than August 6, 2026 per GovInfoSecurity; the actors contacted a security news outlet on August 8 with a proof-of-access screenshot targeting a senior politician, a pressure tactic aimed at the vendor and the state rather than a straight data sale; and Tusk's assessment is that they sought a ransom from the company. Gawkowski said Poland's services are tracking the group and that "the ministry and state services do not negotiate with hackers. We hunt criminals down; we do not strike deals with them." No threat actor name, ransomware brand, or leak site listing has been published in the available sources.
On the downstream containment side, Poland's e-Health Center is replacing the digital certificates medical systems use to connect to P1 as a precaution. Gawkowski said authorities found no evidence the certificates were stolen or misused in the MyDr attack; the rotation is intended to prevent later use of potentially compromised certificates. Officials said the swap should not disrupt e-prescriptions or referrals, and Health Minister Jolanta Sobierańska Grenda said the incident did not pose a threat to Poland's public health services.
What Organizations Should Do
- Inventory your health IT processors and map the controller chain now. If a shared platform is breached, know before the fact who legally owes notification to patients. The MyDr case shows that a processor breach with a thousandfold controller fan-out produces a notification vacuum that attackers will exploit.
- Rotate platform integration credentials and certificates on suspicion, not on proof. Poland's e-Health Center is replacing P1 certificates despite finding no evidence of theft. That is the correct posture: certificate and API-key rotation is cheap relative to a second-stage compromise via trusted machine identity.
- Audit historical data retention in clinical systems. The exposed set reportedly stops around April 2024, meaning data long past operational usefulness still carried full breach impact. Enforce deletion and archival policy on anything holding national identifiers plus clinical detail.
- Prepare an identity-abuse response for non-rotatable identifiers. PESEL, SSN and equivalents cannot be reissued. Stand up credit and identity monitoring guidance, and pre-brief high-exposure staff and executives on targeted blackmail, following the ABW model of proactively contacting prominent affected individuals.
- Watch for breach-notification phishing. With no central notification channel and 12,000 controllers notifying at different speeds, fraudulent "your medical records were leaked" lures are near certain. Publish an authoritative reference page and tell patients and staff what a legitimate notice looks like.
- Log and retain enough to answer the dwell-time question. The central dispute here is whether this was a 2026 intrusion into old data or an older compromise only now surfaced. Organizations that cannot resolve that question from telemetry will face the same ambiguity, and the same credibility problem, in public.
Sources: Tusk government unaware for two years of data breach - Brussels Signal | Hack on Med Software Firm Hits Half of Poland's Population | Poland probes MyDr healthcare software breach ... | Hackers breached a small Polish energy plant via private APN last year | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | UPDATE — Poland's government puts the MyDr breach at nearly 19 mill... | Ransom likely motive in mass breach of Polish medical data