SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-GOVERNMENT- 2026-08-20

MyDr: Criminal Intrusion Exposing Health Records on Nearly 19 Million Poles

"Poland is dealing with what its own digital affairs minister calls "one of the largest incidents in Poland's history": a deliberate criminal intrusion into MyDr, a privately owned Polish company whose software connects…"

Poland is dealing with what its own digital affairs minister calls "one of the largest incidents in Poland's history": a deliberate criminal intrusion into MyDr, a privately owned Polish company whose software connects doctors, clinics and roughly 12,000 medical facilities to P1, the national electronic health platform. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski said on 12 August 2026 that the leak may cover nearly 19 million people, and at a briefing the following day put the stolen database at more than 2 TB (Gazeta Prawna, via ctipilot). The attackers themselves, who contacted the Polish security news service Zaufana Trzecia Strona on 8 August, claimed a more precise figure: 18,814,422 unique national identification numbers. No actor has been identified, no ransom demand has been publicly confirmed, and the government says there is currently no indication of a state-sponsored attack. Accounts differ sharply on one central question, discussed below: how long the data had been exposed before anyone in Warsaw knew.

What Happened

The public timeline starts on Saturday 8 August 2026, when people claiming to be the perpetrators contacted Zaufana Trzecia Strona and said they had accessed the data of around 18.8 million people. As proof, they supplied a screenshot from the compromised database showing the personal data of what the outlet described as "one of the most important politicians in Poland." Zaufana Trzecia Strona published on Monday 10 August. MyDr then confirmed it had "become the target of an external, deliberate criminal activity involving some of our data," without saying at that stage what had been taken.

On Wednesday 12 August, Gawkowski went public, calling the event "an extraordinary and very large incident in terms of the security of Poland's information sphere" and urging Poles to check their exposure through government services and to place a freeze on their PESEL national identity number to blunt identity fraud. By Friday, MyDr said it had identified and removed the cause of the incident and added further security measures, and that it had found no evidence the affected data had been published or otherwise made public. Warsaw district prosecutors opened an investigation into unauthorised access under article 267 of the Polish penal code, an offence carrying up to two years' imprisonment.

The dating of the intrusion is where the sources pull apart, and it should not be smoothed over. Gawkowski's 12 August statement, as reported by Brussels Signal, characterised the leak as having occurred in recent days. Polish authorities cited by The Record said the attackers obtained unauthorised access to historical data held in MyDr systems through April 2024, and that the exposure may not cover all MyDr customers or their patients. Brussels Signal, an OTHER-tier source, goes considerably further, reporting that deputy digital affairs minister Michał Gramatyka said he had no knowledge of a leak of the medical data of nearly 19 million Poles that occurred as far back as two and a half years ago, and framing the episode as a government that went years without noticing. That "two years undetected" characterisation rests on that single OTHER-tier report and on an inference from the April 2024 data cut-off. It is not confirmed by MyDr, by the ministry, or by the prosecutors' filings available here. What can be stated with confidence: the stolen material extends back to at least April 2024, and the government's public account of when the compromise happened has shifted.

What Was Taken

The scale figures come from three different directions and should be read as a range rather than a single number:

Volume is put at more than 2 TB by Gawkowski (reported by Gazeta Prawna). Content, per Notes from Poland and The Record, spans patients' personal information alongside clinical detail including diagnoses and prescriptions, drawn from a platform that also handles electronic medical records and practice management for more than 12,000 facilities. That combination, PESEL numbers plus medical history, is close to a worst case: the identifier is durable and reused across Polish public and financial services, and the medical content is not resettable at all.

Two important negatives. MyDr says it has seen no evidence so far that the data has been published or leaked publicly. And Gawkowski said Poland's e-Health Center was rotating the digital certificates used by medical systems to connect to P1 as a precaution, while stressing that authorities found no evidence those certificates were stolen or misused, and that patients should see no disruption to e-prescriptions or referrals. Health Minister Jolanta Sobierańska-Grenda said on the Monday that the incident posed no threat to public health services.

Why It Matters

The first reason is the notification gap. MyDr is a data processor; the data controllers are the roughly 12,000 individual healthcare facilities that use its software. Per ctipilot's 15 August update, the Polish regulator confirmed the notification duty sits with those clinics, not with the platform. That means there is no single entity that can lawfully tell 19 million people they were affected, and the practical burden falls on thousands of small controllers with wildly uneven capacity. Anyone running a large multi-tenant processor in a regulated sector should read that as the default outcome of their own worst day.

The second is the aggregation effect. Gawkowski's phrase, data "that can be linked together," is the operative risk. A single national identifier joined to clinical records is the raw material for high-credibility phishing, insurance and prescription fraud, and targeted coercion. The attackers' choice to prove access with a senior politician's record, rather than a random citizen's, signals they understand the coercion value of what they hold.

Third, attribution and threat context. Gawkowski has been notably firm that there is no indication of an attack by another state and that cybercriminals are "very likely" responsible, adding: "Nobody will negotiate with anyone. Nobody will give in to any blackmail." That framing matters because it is unusual for Poland, whose critical infrastructure is under sustained state-linked pressure. Weeks earlier, CERT Polska published its analysis of a second December 2025 attack on the Polish energy sector, which SecurityWeek and Infosecurity Magazine tie to the Russian-government-linked APT Sandworm, running in parallel with a coordinated operation against roughly 30 sites including CHP plants and wind and solar dispatch centres. These are separate incidents with no evidentiary link between them, and nothing in the sourcing connects Sandworm to MyDr. But they define the environment Polish defenders operate in: destructive state operations against OT on one side, mass criminal data theft against civilian health infrastructure on the other.

The Attack Technique

For MyDr, the honest answer is that the initial access vector is not public. The company described the event only as "external, intentional criminal activity," said it had identified and removed the cause, and declined to describe the vulnerability or how the attackers got in. Authorities have characterised the access as reaching historical data held in MyDr systems through April 2024. Everything beyond that, including the two-and-a-half-year dwell time implied by Brussels Signal, is unconfirmed. Any vendor or blog asserting a specific exploit chain for MyDr today is ahead of the evidence.

The parallel Polish energy incident, by contrast, is documented in detail by CERT Polska and is worth studying for a genuinely novel technique. Per SecurityWeek, Infosecurity Magazine and Help Net Security, the 29 December 2025 attack on a small CHP plant supplying heat to about 50,000 residents began on an internet-exposed Fortinet VPN and firewall device at a wind farm, and pivoted into the plant's OT network through a private APN, a dedicated mobile network that a distribution system operator establishes with a mobile carrier. CERT Polska says this is the first observed case of a private APN used as an OT attack vector, and warns that the same vulnerable configuration is common in Poland and elsewhere. The attack shut down a steam turbine and the water treatment system used for process water, interrupting cogeneration, though operators restored the plant before heat or power to customers was affected. Notably, staff initially assumed a contractor's engineers had erred during maintenance and filed the report for information only; CERT Polska pursued the cyberattack hypothesis anyway, and the analysis took over three months. Marcin Dudek, head of CERT Polska, presented the findings at DEF CON 34, describing "a three-month hunt through false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated."

What Organizations Should Do

  1. Map your processor and controller boundaries before an incident, not during one. The MyDr case shows what happens when the entity that holds the data has no legal standing to notify the people in it. If you are a processor, pre-agree notification mechanics and message templates with your controllers now; if you are a controller relying on a shared platform, know that the duty lands on you.
  2. Inventory historical data retention in shared platforms. The exposed material reaches back to April 2024. Data your platform no longer needs is still data an attacker can take. Audit what your SaaS and EHR vendors retain, for how long, and where those archives live relative to your production security boundary.
  3. Treat private APNs and cellular links as internet-facing. CERT Polska's finding is that a carrier-provided private APN is not an isolation boundary. Enumerate every cellular modem, DSO-provided link and "assumed isolated" segment, and require authentication and segmentation across them as you would across any untrusted network.
  4. Patch and audit internet-exposed edge devices, starting with VPN and firewall appliances. The energy intrusion began on an internet-connected Fortinet device at a peripheral site. Peripheral assets outside the main OT perimeter are routinely the least-monitored and the most useful to an attacker.
  5. Rotate credentials and certificates that touch shared national platforms, even absent proof of theft. Poland's e-Health Center rotated P1 connection certificates as a precaution with no evidence of compromise. That is the correct posture: the cost of rotation is small next to the cost of a valid certificate surfacing months later.
  6. Do not write off unexplained operational faults as human error. The CHP plant disruption was initially logged as a contractor mistake and only reported for information. CERT Polska caught it because it investigated anyway. Build a path for "probably just an engineering error" events to reach security review.
  7. If you hold citizen identifiers plus sensitive records, plan for the fraud wave, not just the breach. Poland's response leaned on public PESEL freezes and identity-check services. Equivalent guidance, published fast and in plain language, is the part of incident response that actually protects the affected population.

Sources: Tusk government unaware for two years of data breach - Brussels Signal | Poland probes MyDr healthcare software breach potentially affecting... | Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy F... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | Poland hit by theft of 19 million patients’ data from medical platf... | UPDATE — Poland's government puts the MyDr breach at nearly 19 mill... | Medical data breach exposes information of 19 million Poles - TRT W...