SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-HEALTH-DATA 2026-08-15

MyDr: Criminal Extortion Breach Exposes 19 Million Polish Patient Records

"Poland's Ministry of Digital Affairs confirmed on 12 August 2026 that MyDr, a private electronic medical records provider serving roughly 12,000 healthcare facilities nationwide, was breached and had patient data stolen…"

Poland's Ministry of Digital Affairs confirmed on 12 August 2026 that MyDr, a private electronic medical records provider serving roughly 12,000 healthcare facilities nationwide, was breached and had patient data stolen at a scale approaching the entire Polish population. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski put the exposure at nearly 19 million people and called it "one of the largest incidents in Poland's history." The stolen dataset is reported at more than 2 TB. Prime Minister Donald Tusk said the motive appears to be criminal extortion rather than espionage, and the ministry has said there is currently no indication of a state-sponsored attack. The attackers remain unidentified and the initial access vector has not been disclosed.

Figures for the affected population vary slightly by source and by who is speaking. The self-identified perpetrators told Polish security outlet Zaufana Trzecia Strona they held data on approximately 18.8 million people; Gawkowski and the Ministry of Digitalisation describe "nearly 19 million" citizens (reported by Notes From Poland, Anadolu Agency, Pollar and EU Startups News); Brandsit reports that MyDr itself confirmed the loss of around 19 million records. The practical range is 18.8M to 19M, and no source has yet published a deduplicated, verified count.

What Happened

According to prosecutor Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office, an unauthorised actor gained access to MyDr's servers no later than 6 August 2026 by breaking or circumventing IT security measures. The offence as currently charged carries a penalty of up to three years' imprisonment.

The public timeline, drawn primarily from Pollar and Notes From Poland, runs as follows. On the Saturday following the intrusion, the alleged perpetrators contacted Zaufana Trzecia Strona directly, passing over a portion of the stolen data along with a screenshot from the compromised database showing the personal records of, in Z3S's description, "one of the most important politicians in Poland." Z3S published first, on the Monday. Investigators opened actions ex officio on 11 August. On 12 August the Ministry of Digitalisation confirmed the attack and Poland's Central Cybercrime Bureau (CBZC) formally launched its investigation. On 13 August, Tusk and Gawkowski held separate press conferences.

MyDr acknowledged that it had "become the target of an external, deliberate criminal activity involving some of our data." Tusk characterised the intrusion as using "very sophisticated techniques and methods" while stating that "the motivation appears to be purely criminal" and that much points to a ransom extortion attempt against the company. That framing is consistent with the ministry's position that this is not currently assessed as state-sponsored activity, though attribution remains open and no group has been named.

One structural detail matters for scoping. MyDr has been part of the Docplanner group since 2023, alongside the ZnanyLekarz booking platform. Brandsit reports, citing information provided to CRN, that the two systems are separate and do not exchange data, and that the ZnanyLekarz database was not breached. That claim rests on a single OTHER-tier report and should be treated as unconfirmed until Docplanner or the regulator says so directly.

What Was Taken

The stolen archive is described across sources as exceeding 2 TB. Per Pollar, citing the Ministry of Digitalisation, it contains names, PESEL national identification numbers, phone numbers, email addresses, doctors' visit notes and prescription information. Notes From Poland adds diagnoses and prescriptions to the medical category.

That combination is close to worst case for a national population. PESEL is a durable, non-rotatable identifier used across Polish banking, government and telecoms identity checks; unlike a password it cannot be reset, and unlike a payment card it cannot be reissued. Pair it with a verified name, phone number and email address and you have a functioning identity kit. Add clinical notes and prescription history and you have context that makes social engineering dramatically more credible.

The exposure is also involuntary in a way most breaches are not. MyDr operates as technological backbone infrastructure for clinics and private practices, handling electronic medical records, appointment management, e-prescriptions and e-sick notes. As Brandsit notes, patients may sit in the MyDr database without ever having heard of the brand, having only ever visited their own local clinic. There was no account to create and no terms to accept.

Why It Matters

This is a supplier-concentration failure, not a hospital failure. A single software vendor aggregated the medical records of what amounts to roughly half of Poland's population across 12,000 facilities, and one intrusion collapsed the security posture of all of them simultaneously. Every downstream clinic inherited the vendor's blast radius whether or not it had any visibility into the vendor's controls.

The abuse path is direct. Gawkowski urged Poles to use government services to check whether their data is affected and to "lock" their PESEL number to block fraudulent credit and identity operations, which is a tacit acknowledgement that identity-theft exploitation is expected rather than hypothetical. Brandsit flags the second-order risk: phishing armed with a target's real diagnoses, real prescriptions and real doctor's notes defeats the usual "does this message know things about me" heuristic entirely. Expect fake pharmacy notifications, insurance follow-ups and clinic callbacks to follow.

The extortion framing carries its own timeline. If Tusk's assessment is correct and this is a ransom play against MyDr, the dataset's public exposure depends on a negotiation outcome nobody outside the parties can see. A partial leak to a journalist plus a screenshot of a senior politician's records is textbook pressure escalation, and non-payment typically means broader release.

Context matters for scale, too. Brandsit reports that cybersecurity incidents in Poland rose 144 percent year on year in 2025. Poland is currently absorbing sustained, varied pressure across sectors.

The Attack Technique

MyDr's initial access vector has not been publicly disclosed. The prosecutor's office has confirmed only that security measures were broken or circumvented on or before 6 August 2026, and Tusk described the techniques as sophisticated. Beyond that, anyone claiming to know how the attackers got in is guessing. The three-month CERT Polska investigation into the energy-sector incidents referenced below is a useful reminder of how long credible root-cause analysis actually takes.

For contrast, and it is contrast rather than connection, the other major Polish incident in the current reporting cycle is technically documented in full. CERT.PL published a post-mortem on a second December 2025 attack against Polish energy infrastructure, disclosed by CERT Polska head Marcin Dudek at DEF CON 34 and covered by SecurityWeek, Infosecurity Magazine and Help Net Security. That intrusion, attributed to the Russian state-linked APT Sandworm and described as purely destructive, ran a chain that started at an internet-facing FortiGate VPN and firewall at a wind farm, pivoted through a Teltonika cellular router on the same network, and used an SSH tunnel to reach a private Access Point Name network operated by a distribution system operator. Repeated APN scanning surfaced a WAGO PFC200 PLC at a combined heat and power plant serving 50,000 residents, its web interface reachable over the APN and protected only by default admin credentials. From there the actors reached the plant's OT network over SSH, located three Siemens PLCs, and switched them to STOP mode with a password preventing state changes or control-logic modification. A steam turbine and the process-water treatment system shut down, interrupting cogeneration. Operators restored service before customer heat or electricity supply was affected. CERT Polska calls it the first documented case of OT access via a private APN and warns the same vulnerable configuration is common in Poland and elsewhere.

These are two separate incidents with different actors and different objectives. The energy attacks are attributed to a Russian state APT and were destructive; the MyDr breach is currently assessed as criminal extortion with no state indication. Reporting them together reflects the pressure Poland is under, not a shared campaign.

What Organizations Should Do

  1. Inventory your healthcare and identity data suppliers, then map what each one actually holds. The MyDr pattern is a vendor nobody in the org chart thinks about holding the crown jewels for 12,000 downstream customers. If you cannot name every third party that can read your patient or customer identity records, that is the first gap to close.
  2. Contractually require breach notification timelines and incident evidence from suppliers, not just security attestations. MyDr customers learned the scope from a journalist and a press conference. Build in obligations for immediate notification, log preservation and access to forensic findings.
  3. Audit every internet-reachable and network-reachable device for default credentials right now. A WAGO PFC200 protected by nothing but the shipped admin password was the pivot into an OT network in the CERT Polska case. This is the single cheapest control with the highest demonstrated payoff in current Polish incident data.
  4. Stop treating private APNs, cellular routers and DSO-managed links as isolated. CERT Polska explicitly warns the vulnerable APN configuration is common internationally. Enumerate what is reachable from your carrier-managed network segments, segment the APN from OT, and monitor for scanning inside it.
  5. Assume identity-verification questions based on personal or medical data are now compromised for the Polish population. Move help desks, patient portals and financial services off knowledge-based verification that relies on PESEL, address, phone or clinical history. Attackers holding this dataset will pass those checks.
  6. Prepare for medically-informed phishing across your user base. Brief staff and customers that fraudulent messages may accurately cite real diagnoses, prescriptions and appointment details, and give them a verified out-of-band channel to confirm anything clinical or financial.
  7. For individuals in scope: lock your PESEL through government services now, as the ministry advised, and monitor for credit applications you did not initiate. This is the one mitigation available to people who never chose to be in the database.

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy F... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Previously unseen entry vector used to breach Polish energy plant -... | Poland hit by theft of 19 million patients’ data from medical platf... | The MyDr data breach may affect 19 million Poles. The data came fro... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | Polish Healthtech Platform MyDr Hit by Major Data Breach Affecting...