SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-GOVERNMENT- 2026-08-20

MyDr: Unattributed Criminal Intrusion Exposing ~19 Million Polish Patient Records

"Poland's government has confirmed one of the largest data breaches in the country's history: an intrusion into MyDr, a privately owned Polish vendor of electronic health record and practice management software, exposing…"

Poland's government has confirmed one of the largest data breaches in the country's history: an intrusion into MyDr, a privately owned Polish vendor of electronic health record and practice management software, exposing personal and medical data on close to 19 million people. Deputy Prime Minister and digital affairs minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history" and said the stolen database exceeds 2 TB. Figures for the number of people affected range from 18,814,422 unique national identification numbers, the count given by the alleged attackers themselves to the Polish security news service Zaufana Trzecia Strona, to the government's rounded "nearly 19 million." Roughly 12,000 medical facilities use MyDr's services, according to the digital affairs ministry. Warsaw district prosecutors have opened an investigation under article 267 of the Polish penal code, which carries a sentence of up to two years.

What Happened

The incident surfaced from the attacker side, not the victim side. Zaufana Trzecia Strona reported on Monday 10 August 2026 that it had been contacted two days earlier, on Saturday 8 August, by people claiming to have taken data on around 18.8 million people. To substantiate the claim, they sent the outlet a screenshot from the compromised database showing the personal data of what Zaufana Trzecia Strona described as "one of the most important politicians in Poland."

MyDr confirmed shortly afterwards that it had "become the target of an external, deliberate criminal activity involving some of our data." On Wednesday 12 August, Gawkowski publicly acknowledged the breach, describing it as "an extraordinary and very large incident in terms of the security of Poland's information sphere," and urged Poles to check government services for exposure and to "block" their PESEL national identity number against fraudulent use. By Friday, MyDr said it had identified and removed the cause of the incident and added further security controls. It has not disclosed the vulnerability or the access method.

MyDr's software connects healthcare providers to P1, Poland's national e-health platform underpinning electronic prescriptions and referrals. As a precaution, Gawkowski said the country's e-Health Centre began replacing the digital certificates that medical systems use to authenticate to P1. Authorities stated they found no evidence that certificates were stolen or misused; the rotation is pre-emptive, intended to strip value from any credential material that may have been taken without detection. Officials said patient-facing services should not be disrupted. Health Minister Jolanta Sobierańska-Grenda said on Monday that the incident did not pose a threat to public health service delivery.

Accounts Differ On The Timeline

The most consequential disagreement in the public record is when this actually happened, and it is not resolved.

Gawkowski's 12 August statement, as reported by Brussels Signal, framed the leak as having occurred "in recent days." Brussels Signal, an OTHER-tier source, reports that deputy digital affairs minister Michał Gramatyka separately said he had no knowledge of a leak of medical data on nearly 19 million Poles dating back roughly two and a half years, and the outlet builds its headline claim of a two-year detection gap on that. That specific "the government did not know for two years" framing rests on a single OTHER-tier source and should not be treated as established.

What is better supported: The Record reports that Polish authorities said the attackers obtained unauthorised access to historical data held in MyDr systems through April 2024, and that the exposure may not cover all MyDr customers or their patients. A data set that terminates in April 2024 is consistent with an intrusion or a data staging event dating back well over two years, but a cutoff date is not the same evidence as a confirmed dwell time. Poland has not published an intrusion timeline, an initial access date, or a dwell-time finding. Defenders should read the situation as: the state has confirmed the scale and the criminal nature of the incident, and has not yet confirmed how long the access went unnoticed.

What Was Taken

MyDr's holdings include patient personal information alongside clinical detail such as diagnoses and prescriptions. The government's stated volume is more than 2 TB, attributed to Gawkowski at a briefing following a meeting of the Joint Cybersecurity Operations Centre and reported by Gazeta Prawna on 13 August. The count of affected individuals is best expressed as a range: 18,814,422 unique identification numbers per the attackers' own claim relayed by Zaufana Trzecia Strona, against "nearly 19 million" as stated by the Polish government. More than 12,000 medical facilities are implicated.

Two caveats matter. First, MyDr has said it has found no evidence so far that the affected data has been published or otherwise made publicly available, meaning no confirmed leak-site or forum posting at time of writing. Second, the attacker-supplied figure is a claim by an interested party; it happens to align closely with the government's independent estimate, which strengthens it, but it remains a claim.

The population figure is the tell. Poland has roughly 38 million residents. A data set containing close to 19 million PESEL numbers linked to diagnoses and prescription histories represents something close to half the country, and the disclosed politician's record demonstrates the set is not filtered to ordinary citizens. Medical data is not rotatable. A PESEL can be administratively frozen against credit fraud, but a diagnosis history is exposed permanently once it leaves.

Why It Matters

The structural lesson here is about legal architecture, not malware. MyDr is a data processor, not a controller. The controllers are the roughly 12,000 individual clinics and healthcare facilities that use the platform. Poland's regulator has confirmed that the GDPR notification duty accordingly sits with those thousands of clinics, not with the platform that was actually breached. The observation was initially made by reporting outlets and has since been settled by the state. The practical result is that there is no single entity that can notify 19 million affected people, and the burden falls on thousands of small organisations, most of which have no breach response capability and, in many cases, may not yet know which of their patients are in the set. Any organisation running a shared-tenant SaaS model in a regulated sector should treat this as a live test case: the processor/controller split that looks clean on a data processing agreement becomes an accountability vacuum at scale.

On attribution, Gawkowski said there is no indication of an attack by Russia or another state and that cybercriminals are "very likely" responsible. That framing is notable given Poland's threat environment, and it changes the expected follow-on activity: financially motivated actors monetise, which means extortion pressure on MyDr or on individual clinics, resale, and downstream fraud, rather than the quiet intelligence exploitation a state operation would imply.

That environment is worth stating plainly, because it is the backdrop against which Warsaw is making these calls. In a report published in August 2026, CERT Polska disclosed a second, previously unreported attack on the country's energy sector, conducted on 29 December 2025 in parallel with the already-known campaign against roughly 30 wind and solar sites and a large combined heat and power plant. The second target was a smaller CHP plant supplying heat to about 50,000 residents; the attackers switched off programmable logic controllers and password-protected access to them, shutting down a steam turbine and the process-water treatment system and interrupting cogeneration. Attribution for those energy attacks differs by outlet: SecurityWeek ties them to the Russian state-linked APT known as Sandworm, while BleepingComputer attributes them to the Russian-linked Electrum group. Those incidents are entirely separate from the MyDr breach and there is no reported connection between them. The point is the operating context: Polish defenders are absorbing a mass health data compromise while simultaneously handling destructive OT intrusions.

The Attack Technique

For MyDr, the honest answer is that it is not known. The company described "external, intentional criminal activity" and said it had identified and removed the cause, but disclosed neither the vulnerability nor the access path. No initial access vector, no malware family, no infrastructure, and no named actor have been published. Anyone claiming a specific technique for this breach is ahead of the evidence.

Where technique detail does exist in the current Polish reporting, it belongs to the unrelated energy sector case, and it is worth reading for its own sake. CERT Polska found that the attackers reached the small CHP plant's OT network via a private APN, the dedicated mobile network a distribution system operator sets up with a mobile carrier for its distributed energy resource sites. CERT.PL says this is the first observed case of a private APN being used as an attack vector into OT. The chain started at an internet-facing FortiGate VPN and firewall device at a wind farm, then pivoted through a Teltonika cellular router on that network. The enabling flaw was a misconfiguration: "The attack was made possible, among other factors, by a misconfiguration that allowed arbitrary devices within the private APN network to communicate with one another." CERT.PL warns the same vulnerable configuration is commonly found in Poland and in other countries. Notably, the attack landed during scheduled maintenance, so staff initially assumed a contractor engineering error and filed it for information only; CERT Polska investigated on suspicion anyway and needed more than three months of analysis, which is why the case was omitted from the initial report. Marcin Dudek, head of CERT Polska, presented the findings at DEF CON 34 in Las Vegas, describing "a three-month hunt through false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated."

What Organizations Should Do

  1. Inventory your processors and know who notifies. If a shared platform holding your customers' data is breached, determine now whether you or the vendor carries the controller obligation, and whether you could identify and contact your affected subjects without the vendor's help. The MyDr case shows what happens when 12,000 organisations discover that answer during an incident.
  2. Rotate machine identities pre-emptively after any platform compromise. Poland's e-Health Centre replaced P1 connection certificates despite finding no evidence they were stolen. Certificates, API keys, and service credentials held by a breached integrator should be treated as compromised on suspicion, because absence of evidence in an unscoped incident is not evidence of absence.
  3. Set retention limits and enforce them. A live system holding queryable historical records back through April 2024 and beyond turns any single intrusion into a multi-year exposure. Archive cold data out of internet-reachable production stores.
  4. Build detection for bulk read, not just for intrusion. Nothing in the public record suggests MyDr caught this itself; it surfaced when the attackers emailed a journalist. Alert on anomalous volume egress and mass record enumeration from application and database tiers, and rehearse the query that answers "how much did they take."
  5. Treat "probably human error" incidents as unproven. CERT Polska only found the CHP plant attack because it declined to accept the maintenance-error explanation staff had filed for information only. Give operators a low-friction path to report anomalies and a policy that unexplained OT disruptions get a security review regardless of the initial assumption.
  6. Audit flat mobile and cellular segments. If you run a private APN or DSO-provided cellular network for remote sites, verify that devices within it cannot freely reach one another, and enumerate forgotten remote access hardware, edge VPN appliances, and cellular routers sitting between the internet and networks you assume are isolated.
  7. For individuals in Poland: use the government services Gawkowski pointed to in order to check exposure, and consider blocking your PESEL number against fraudulent credit and identity use.

Sources: Tusk government unaware for two years of data breach - Brussels Signal | Poland probes MyDr healthcare software breach potentially affecting... | Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy F... | Hackers breached a small Polish energy plant via private APN last year | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | Poland hit by theft of 19 million patients’ data from medical platf... | UPDATE — Poland's government puts the MyDr breach at nearly 19 mill...