Poland's Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski confirmed on 12 and 13 August 2026 that MyDr, one of the country's largest electronic medical record (EMR) software providers, suffered a cyberattack resulting in the theft of health and identity data belonging to nearly 19 million people. Prime Minister Donald Tusk characterised the motive as "purely criminal" with strong indications of a ransom demand against the company. Gawkowski stated there is currently no evidence of involvement by another state. The stolen dataset is described by Gawkowski as exceeding 2 TB. In a country of roughly 38 million people, that record count implicates approximately half the population.
A sourcing caveat up front: no vendor advisory, regulator filing, or CERT Polska report on this incident was available at the time of writing. Every detail below traces to government press conferences, the Warsaw district prosecutor's office, or Polish and international press reporting on them. Treat figures as official-but-preliminary.
What Happened
MyDr supplies EMR software used by roughly 12,000 healthcare facilities across Poland (Pollar, Brandsit), covering electronic medical records, appointment management, e-prescriptions, and e-sick notes. It is a technology backbone rather than a consumer brand, which means large numbers of affected patients have never heard of it and only ever interacted with their own local clinic.
Accounts differ on the timeline, and the difference matters:
- Prosecutor Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office, states the perpetrator gained unauthorised access to MyDr's servers no later than 6 August 2026, by breaking or circumventing IT security measures (Pollar).
- TVP World describes the breach as having "took place on Wednesday" (12 August), which appears to conflate the date of public confirmation with the date of intrusion.
The prosecutor's date is the more authoritative of the two and implies a dwell or exposure window of at least six days before public disclosure. Per Pollar's reconstruction: first investigative actions were taken ex officio on Monday 11 August; the Ministry of Digitalisation confirmed the attack on 12 August as the CBZC (Central Bureau for Combating Cybercrime) formally launched its investigation; Tusk and Gawkowski held press conferences on 13 August. Under the cited Polish provision, the offence carries a penalty of up to three years' imprisonment.
Notably, a portion of the stolen data was sent to the editorial team of the Polish security site Zaufana Trzecia Strona (Pollar). That is a proof-of-possession move typical of extortion operations seeking leverage or publicity, and it is the strongest independent corroboration that the actor genuinely holds the data.
Gawkowski said the exploited vulnerability has since been identified and patched. Neither the vulnerability nor the threat actor has been publicly named. State security services are reportedly tracking the group.
One scope limitation worth recording: MyDr has been part of the Docplanner group (which also owns ZnanyLekarz) since 2023. Brandsit reports, citing information provided to CRN, that the two platforms run on separate systems that do not exchange data, and that there is no indication of a ZnanyLekarz breach. That is single-source and vendor-adjacent, so treat it as a claim rather than a verified boundary.
What Was Taken
Reported record counts are consistent across all eight sources at "nearly 19 million," but the unit is not consistent, and this is the sharpest ambiguity in the story:
- Gawkowski, quoted by Anadolu Agency via TVP World, said: "As confirmed by the company itself, 19 million records were stolen, containing various types of data that can be linked together."
- Brandsit similarly reports the company confirmed the loss of "around 19 million records," while framing the population impact as "may affect" up to 19 million Poles.
- Pollar and EU Startups News report the figure as data belonging to nearly 19 million citizens.
Records and affected individuals are not the same measure. A single patient can generate many records. Until MyDr or Poland's data protection authority publishes a deduplicated figure, the honest reading is: approximately 19 million records, with the number of distinct individuals affected not yet independently established and plausibly lower.
Data categories reported by Pollar include names, PESEL national identification numbers, phone numbers, email addresses, doctors' visit notes, and prescription information. TVP World separately cites prescription, medication, and other sensitive patient data. The combination of PESEL plus clinical notes plus contact details is close to a worst-case package: PESEL is a permanent, non-rotatable identifier used for banking, tax, and government services, and clinical notes are irreversible disclosures that cannot be reissued the way a card number can.
Gawkowski said the stolen records have not appeared in the public domain or been offered for sale, and that steps are being taken to prevent onward sale, while explicitly acknowledging he cannot guarantee the data will never leak. Poland's domestic intelligence service (ABW) has proactively contacted prominent public figures whose data was affected, specifically to reduce blackmail risk against them. That is an unusual and telling countermeasure: it concedes that individual-level extortion, not just corporate extortion, is a live threat model here.
Why It Matters
This is a supply chain compromise wearing a healthcare costume. MyDr itself holds no patients; 12,000 clinics do. The concentration of records inside a single mid-market software vendor turned one intrusion into a national-scale exposure. Every organisation that runs a shared EMR, practice management platform, or billing intermediary should read the 12,000-to-1 ratio as a description of their own aggregate risk, not Poland's.
The extortion posture is the second lesson. Tusk described "very sophisticated techniques and methods" and a financially motivated actor. Gawkowski's response was categorical: "The ministry and state services do not negotiate with hackers. We hunt criminals down; we do not strike deals with them," and separately, "Nobody will negotiate with anyone. Nobody will give in to any blackmail." A hard public non-payment stance from a national government raises the probability that the data eventually gets dumped or auctioned, which is precisely why Gawkowski declined to guarantee otherwise. Defenders in the region should plan for the dataset to surface.
Third, the downstream abuse profile is unusually severe. Brandsit notes the realistic consequences extend beyond identity theft to substantially more convincing phishing, because an attacker who knows your prescriptions, your doctor's notes, and your PESEL can impersonate your clinic with high fidelity. Expect Polish-language medical-themed lures, fake pharmacy and e-prescription notifications, and insurance or benefits fraud pretexts. Brandsit also records that reported cybersecurity incidents in Poland rose 144 percent year-on-year in 2025.
The Attack Technique
Be direct: the intrusion vector for MyDr has not been disclosed. What is on record is that the actor "gained unauthorised access to MyDr's servers by breaking or circumventing IT security measures" (prosecutor Skiba, via Pollar), that the exfiltration exceeded 2 TB, that the government calls the tradecraft sophisticated, and that a specific vulnerability was identified and patched after the fact. Anyone publishing a specific CVE, ransomware brand, or intrusion chain for this incident at present is speculating.
Two observations can be made without overreaching. First, moving 2 TB out of a production EMR environment is a loud, sustained egress event; that it completed suggests data loss prevention and egress volume alerting either were absent or were not tuned to trigger. Second, the fact that a patchable vulnerability was found post-incident points toward an exposed, exploitable service rather than a purely credential-driven compromise, though that inference is not confirmed.
Context: Poland Under Sustained Pressure
The MyDr breach lands in a threat environment that Polish authorities have been documenting for months, and it is worth separating the strands rather than blurring them.
A separate and unrelated incident set, reported by BleepingComputer, Security Affairs, and Help Net Security on 10 and 11 August 2026, concerns Poland's energy sector. CERT Polska disclosed a second victim of the destructive 29 December 2025 attacks: a small combined heat and power plant supplying heat to around 50,000 residents. The attacker switched off programmable logic controllers and password-protected access to them, deactivating a steam turbine and the plant's process-water treatment system and interrupting cogeneration. Staff restored the installation before customers lost heat or electricity.
The entry path is the significant part. Per CERT Polska, the attacker first compromised a FortiGate VPN/firewall at a wind farm, pivoted through a Teltonika cellular router, and crossed into the OT network via a private Access Point Name (APN), a dedicated mobile network established by the distribution system operator with a mobile carrier. A misconfiguration allowed arbitrary devices inside that private APN to talk to one another. Help Net Security reports this as the first observed case of OT network access obtained through a private APN. Marcin Dudek, head of CERT Polska, presented the findings at DEF CON 34 and described the investigation as "a three-month hunt through false leads, forgotten remote access devices, wiped industrial hardware, cellular connectivity, and infrastructure that was assumed to be isolated." Maintenance was underway at the plant that day, so staff initially assumed contractor error and filed the report as informational only. The same day's coordinated campaign hit 30 wind and solar installations and a larger CHP plant, destroying equipment beyond repair; BleepingComputer attributes it to an actor believed linked to the Russian Electrum threat group.
The connection to MyDr is contextual, not causal. There is no reported link between the two, and the government explicitly assesses the medical breach as criminal rather than state-sponsored. What the pairing does establish is that Poland is absorbing both destructive state-aligned OT attacks and mass-scale criminal data theft in the same window, and that in both cases the compromise arrived through infrastructure the victims assumed was out of scope: a private mobile network in one, a software vendor in the other.
What Organizations Should Do
-
Inventory your data-holding vendors by record count, not contract value. The MyDr pattern is a low-profile supplier holding a nation's worth of records. Rank third parties by the volume and sensitivity of data they process on your behalf, then audit the top of that list first. Brandsit's takeaway for Polish clinics applies generally: audit IT suppliers more thoroughly and review how patient data is actually secured, contractually and technically.
-
Instrument egress volume, not just perimeter access. A 2 TB outbound transfer should be a paging alert. Baseline normal data movement out of EMR, warehouse, and backup environments, and alert on multiples of that baseline regardless of destination reputation. Detection here is a volume problem before it is a signature problem.
-
Treat internet-facing edge appliances as compromise-assumed. The CERT Polska energy case began at a FortiGate VPN and pivoted through a cellular router. Maintain a live inventory of every VPN concentrator, firewall, and cellular gateway, patch them on a distinct accelerated cycle, and log authentication and configuration changes off-box.
-
Audit "isolated" networks for isolation you have actually verified. Private APNs, management VLANs, and vendor maintenance links routinely fail closed-by-default assumptions. The Polish CHP compromise turned on a misconfiguration permitting arbitrary device-to-device traffic inside a private APN. Test east-west reachability inside these segments rather than trusting the design document.
-
Decide your extortion posture before you need it. Poland's government pre-committed publicly to non-payment. Whatever your organisation's position, settle it now with legal, executive, and insurance stakeholders, and build the corollary plan: regulatory notification timelines, a data-publication contingency, and a communications track for affected individuals.
-
Plan for high-fidelity social engineering against affected individuals. Where breached data enables convincing impersonation, notify proactively about the specific lures to expect. The ABW's outreach to high-risk public figures is the right instinct applied narrowly; organisations should extend targeted warnings to executives, clinicians, and anyone whose exposure makes them a blackmail or spearphishing target.
-
For anyone potentially in the MyDr dataset: PESEL numbers cannot be rotated. Poland offers PESEL-lock mechanisms through government services to block credit issued in your name, and monitoring for medical-themed phishing referencing real prescriptions or visit details should be assumed necessary indefinitely rather than for a fixed monitoring period.
Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Hackers breached a small Polish energy plant via private APN last year | Hackers Cross From IT to OT Through a Private APN in Poland | Previously unseen entry vector used to breach Polish energy plant -... | Ransom likely motive in mass breach of Polish medical data | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | The MyDr data breach may affect 19 million Poles. The data came fro... | Polish Healthtech Platform MyDr Hit by Major Data Breach Affecting...