SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-GOVERNMENT- 2026-08-21

MyDr: Criminal Extortion Crew Steals Medical Data on Nearly 19 Million Poles

"Polish electronic medical documentation vendor MyDr has confirmed a deliberate criminal intrusion into its systems, and the Polish government now estimates the resulting data theft touches nearly 19 million people…"

Polish electronic medical documentation vendor MyDr has confirmed a deliberate criminal intrusion into its systems, and the Polish government now estimates the resulting data theft touches nearly 19 million people, roughly half the national population, across more than 12,000 healthcare facilities. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski called it "an extraordinary and very large incident in terms of the security of Poland's information sphere" and, per the ctipilot.ch briefing summary, "one of the largest incidents in Poland's history." Prime Minister Donald Tusk said the motive appears to be a straightforward ransom extortion attempt. Sitting underneath the technical story is a harder political one: accounts differ sharply on how long this data was exposed, with Brussels Signal reporting that a sitting deputy digital affairs minister said he had no knowledge of a medical data leak of this scale dating back roughly two and a half years.

What Happened

The public timeline starts on August 8, 2026, when the Polish IT security news service Zaufana Trzecia Strona was contacted directly by people claiming to be the perpetrators. The outlet published on August 10. On August 12, Gawkowski publicly acknowledged the breach, and Polish authorities opened a formal investigation the same day. Warsaw district prosecutors are pursuing unauthorised access to MyDr's systems obtained no later than August 6, an offence under Article 267 of the Polish penal code carrying a maximum sentence of two years. Poland's Central Bureau for Combating Cybercrime is running the technical investigation, and the matter was escalated through the Joint Cybersecurity Operations Centre.

MyDr said it had identified and removed the cause of the incident and introduced additional security measures, describing the event as "external, intentional criminal activity." Gawkowski separately stated the exploited vulnerability had been identified and patched. Neither MyDr nor the government has disclosed what the vulnerability was or how initial access was achieved.

On attribution, the government has been consistent and unusually specific about what it is not seeing. Gawkowski said there is no indication of an attack by Russia or another state actor and that cybercriminals are "very likely" responsible. Tusk said the attack used "very sophisticated" methods but that "the motivation appears to be purely criminal. There are many indications that this was an attempt to extort a ransom." Gawkowski's position on negotiation was blunt: "The ministry and state services do not negotiate with hackers. We hunt criminals down; we do not strike deals with them." The threat actor remains unidentified.

What Was Taken

Figures vary by source and by who is doing the counting, and the differences matter:

The data itself is about as sensitive as civilian records get: prescription data, medication histories, and other patient health information, alongside PESEL numbers. The PESEL is Poland's lifetime national identifier and functions far more broadly than a US Social Security number, used routinely for rentals, utilities, and identity verification. It cannot practically be rotated. That combination, permanent identifier plus medical history, is the raw material for both financial fraud and targeted blackmail.

The blackmail risk is not hypothetical. The attackers sent Zaufana Trzecia Strona a screenshot from the compromised database showing the personal data of what the outlet described as "one of the most important politicians in Poland." Poland's domestic intelligence service, the ABW, has been contacting prominent public figures whose data was affected in order to reduce blackmail exposure.

As of the most recent statements, Gawkowski said the records had not appeared publicly or been offered for sale, and MyDr said it had found no evidence the affected data had been published. Gawkowski acknowledged there is no guarantee that holds.

Where the Accounts Diverge

This is where the reporting genuinely conflicts, and readers should not be handed false precision.

On the age of the data. Polish authorities told The Record the attackers accessed historical data held in MyDr systems through April 2024, and that it may not cover all MyDr customers or their patients. MyDr's own statement aligns: "Our investigation indicates that the data involved in the incident is likely historical, dating back to 2024 and earlier." Under that reading, the intrusion is recent and the stolen archive is old.

On the age of the breach. Brussels Signal reports something materially different: that deputy digital affairs minister Michał Gramatyka said he had no knowledge of a leak involving the medical data of nearly 19 million Poles "that occurred as far back as two and a half years ago," and contrasts this with Gawkowski's August 12 statement that the leak had occurred in recent days. Under that reading, the exposure predates the current disclosure by years and went undetected by the state.

These are not the same claim. "Old data stolen recently" and "data stolen two years ago and only now noticed" have very different accountability implications, and only one OTHER-tier source advances the second version. We are not treating the two-year-undetected framing as confirmed. What can be said with confidence is that both the government and the vendor place the content of the stolen data in 2024 or earlier, and that a serving deputy minister has publicly distanced himself from prior knowledge of a leak of this scale.

On the intrusion date. TVP World reports the breach "took place on Wednesday," while prosecutors are investigating access obtained no later than August 6. The prosecutorial framing is the stronger evidence; the discrepancy likely reflects disclosure date versus intrusion date.

Why It Matters

Three things make this brief worth reading beyond the headline number.

The notification gap is structural, not incidental. MyDr is a data processor, not a controller. The controllers are the roughly 12,000 individual clinics and practices using its software. Per the ctipilot.ch update, the Polish regulator has confirmed that the GDPR notification duty sits with those 12,000 clinics rather than with the platform. That means there is no central mechanism to tell 19 million people they were affected. It has to happen 12,000 times, at wildly varying levels of competence and resourcing. Any organisation whose breach-response plan assumes the platform vendor will handle notification should re-read its data processing agreements this week.

Concentration risk in national health infrastructure. MyDr's software connects providers to P1, Poland's nationwide electronic health platform underpinning e-prescriptions and referrals. A single mid-market vendor became the aggregation point for half a country's medical records. As a precaution, Poland's e-Health Center is replacing the digital certificates that medical systems use to authenticate to P1, even though Gawkowski said authorities found no evidence the certificates were stolen or misused. Officials said patients should not see service disruption. Health Minister Jolanta Sobierańska-Grenda said the incident posed no threat to public health delivery.

The strategic backdrop. The government's insistence that this is ordinary crime rather than state activity lands in a country that has spent the past year absorbing the opposite. CERT.PL disclosed in August 2026 that in late December 2025, threat actors linked to the Russian state, specifically Sandworm, hit roughly 30 Polish energy sites with what SecurityWeek characterised as a "purely destructive" objective, permanently damaging some ICS devices. A second, parallel intrusion at a smaller combined heat and power plant serving around 50,000 residents shut down a steam turbine and a water treatment system. Poland is being worked from both directions: financially motivated crews against civilian data, and state crews against physical infrastructure. Defenders in the region should not let a "criminal, not state" attribution on one incident lower the threshold on the other.

The Attack Technique

For MyDr specifically, the entry vector has not been disclosed. Authorities say access was obtained through the internet to all or part of MyDr's systems no later than August 6. MyDr declined to detail the vulnerability or the access path, and Gawkowski confirmed only that it has been patched. Tusk's "very sophisticated" characterisation is a political assessment, not a technical one, and should be discounted accordingly until CBZC or CERT.PL publishes findings.

The energy-sector intrusions, by contrast, are documented in detail and are worth studying because the tradecraft is novel. Per CERT Polska's report, presented by CERT Polska head Marcin Dudek at DEF CON 34, the December 29 attack on the smaller CHP plant is the first observed case of attackers reaching an OT network through a private APN, a dedicated mobile network established between a distribution system operator and a mobile carrier. The intrusion began at an internet-exposed Fortinet VPN and firewall device located at a wind farm, then pivoted through the cellular path into the plant's OT environment. CERT.PL warns the same vulnerable configuration is common in Poland and internationally.

Two operational details from that case deserve emphasis. First, the attack happened during scheduled maintenance, so staff initially assumed a contractor engineering error and filed the incident informationally rather than as a security event. CERT Polska investigated anyway because it was aware of similar events elsewhere. Second, per Help Net Security, analysis took more than three months, which is why the incident was omitted from the original report. Dudek described it as "a three-month hunt through false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated."

What Organizations Should Do

  1. Audit your processor relationships for notification liability. Identify every SaaS or software vendor holding personal data where you are the controller. Confirm in writing who notifies data subjects and the supervisory authority if that vendor is breached, and what the SLA is. The MyDr case shows a scenario where the vendor legally cannot notify and thousands of small controllers must.
  2. Inventory and rotate machine identities used for platform integration. Poland's e-Health Center is replacing P1 certificates as a precaution despite no evidence of theft. Adopt the same posture: know every certificate, API key, and integration credential a compromised vendor could plausibly have touched, and be able to rotate them without service disruption.
  3. Audit private APN and cellular paths into OT. If a DSO, carrier, or contractor has provisioned a private APN reaching your industrial network, treat it as an internet-adjacent path, not an isolated one. Segment it, monitor it, and validate that reachability from that APN is limited to what the process actually requires.
  4. Patch and inventory internet-facing edge appliances, especially at remote sites. The energy-sector intrusion started at a Fortinet VPN device at a wind farm. Unmanned or lightly staffed remote facilities are where forgotten remote-access hardware accumulates.
  5. Change the default assumption on operational anomalies. Plant staff initially wrote off a turbine shutdown as contractor error. Build a rule that unexplained OT disruptions during maintenance windows get a security triage pass before being closed as human error, and preserve logs accordingly.
  6. Prepare for identity abuse that outlives the breach. PESEL numbers, like other national lifetime identifiers, cannot be reissued at scale. Organisations that accept such identifiers as proof of identity should raise verification requirements now, and high-profile individuals in affected populations should assume targeted extortion attempts, as the ABW's outreach to public figures implies.
  7. Assume the "not yet published" status is temporary. Both MyDr and the government say the data has not surfaced publicly or for sale. Gawkowski explicitly declined to guarantee that. Plan monitoring and response for the leak-site publication scenario rather than the containment scenario.

Sources: Tusk government unaware for two years of data breach - Brussels Signal | Hack on Med Software Firm Hits Half of Poland's Population | Poland probes MyDr healthcare software breach ... | Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy F... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish ... | UPDATE — Poland's government puts the MyDr breach at nearly 19 mill... | Ransom likely motive in mass breach of Polish medical data