Poland's deputy prime minister and digital affairs minister, Krzysztof Gawkowski, told reporters on Wednesday, 12 August 2026 that personal and medical data on almost 19 million people had been taken in a cyberattack on MyDr, one of the country's largest providers of electronic medical documentation. "We are dealing with one of the largest incidents in Poland's history," Gawkowski said, per Notes from Poland (republished via europesays.com). The stolen database is said to exceed 2 TB, according to the Polish Press Agency's account of the minister's briefing. Figures reported for the victim count vary slightly by source: Gawkowski publicly cited "19 million records" as confirmed by the company, while the attackers themselves claimed 18,814,422 unique PESEL national identification numbers, a figure relayed by the Polish security site Zaufana Trzecia Strona and reported by Poland Daily 24 and Anadolu Agency. Notably, the same minister struck a materially more cautious note in written comments the same week, and that gap is the single most important caveat in this story.
What Happened
The public timeline begins on Saturday, 8 August, when the alleged perpetrators contacted Zaufana Trzecia Strona, an independent Polish IT security news service, claiming to have accessed data on roughly 18.8 million people. To substantiate the claim they reportedly sent a screenshot from the compromised database showing the personal data of what ZTS described as "one of the most important politicians in Poland."
ZTS published first, on Monday 10 August. The same day, Gawkowski posted the first official government statement on X, saying the relevant services had been notified and were working to establish the circumstances of the attack while supporting the company in securing its IT infrastructure. At that point, as Poland Insight reported from PAP wire copy, the official framing was narrower: indications of "possible unauthorised access," with no confirmation that patient or customer data had been exfiltrated. MyDr separately notified its own customers, the medical facilities and doctors who use the platform, of the possible unauthorised access.
Shortly after the ZTS story, MyDr confirmed it had "become the target of an external, deliberate criminal activity involving some of our data."
On Wednesday 12 August, following a session of Poland's Joint Cybersecurity Operations Centre, Gawkowski held the press conference that produced the 19 million figure and the 2 TB database size. MyDr issued an update the same day saying that, at the time of writing, there was no evidence the data had been published anywhere.
Accounts differ on how settled the finding is. In his briefing Gawkowski said, "As confirmed by the company itself, 19 million records were stolen, containing various types of data that can be linked together." In written comments, however, he wrote: "At this stage of the investigation, it is not yet possible to conclusively confirm that a data breach occurred. However, there are many indications that an unauthorized person may have gained access to the data." Both statements are attributed to the same minister within the same news cycle. Treat the 19 million figure as the government's working number and the attackers' claim as unverified until MyDr or Poland's data protection authority publishes a reconciled count.
What Was Taken
MyDr stores electronic medical documentation on behalf of thousands of healthcare facilities across Poland. Reporting describes the exposed data as patients' personal information combined with clinical detail, specifically diagnoses and prescriptions (Notes from Poland) and appointment records and health problems (Poland Daily 24, via Anadolu Agency). MyDr belongs to the Docplanner group, the same corporate group behind the widely used ZnanyLekarz booking platform.
The volume claims, stated as a range and attributed:
- ~19 million records / people as stated by Gawkowski at the 12 August briefing, described by him as confirmed by MyDr.
- 18,814,422 unique PESEL numbers as claimed by the attackers and relayed by Zaufana Trzecia Strona.
- Over 2 TB of data in the stolen database, per Gawkowski via PAP.
The PESEL count is the number that matters operationally. PESEL is Poland's permanent national identifier, used for tax, banking, healthcare, and identity verification. It cannot be rotated. Roughly 19 million is close to half of Poland's population, and because the records reportedly combine identity data with clinical data "that can be linked together," in the minister's phrasing, the material supports both financial fraud and targeted coercion or extortion against named individuals. The reported screenshot of a senior politician's record is a deliberate signal that the dataset contains high-value targets.
Why It Matters
This is not an isolated event. It lands on top of a documented and steepening trend against Polish healthcare and critical infrastructure.
Data from Poland's e-Health Centre, cited in a CSIRT CeZ report and covered by Poland Insight, records 1,441 cybersecurity incidents affecting the healthcare sector in 2025, more than 60% above the prior year, with online fraud, vulnerable exposed services, and account compromise among the most common categories.
The wider Polish attack surface has drawn independent scrutiny. TechCrunch reported on 7 August that security researchers who scanned Polish internet-facing infrastructure found courts, hospitals, and airports at risk of compromise. And on the operational technology side, Help Net Security reported CERT Polska's disclosure, presented by CERT Polska head Marcin Dudek at DEF CON 34, of the first observed case of attackers reaching an OT network through a private APN, a dedicated mobile network set up between a distribution system operator and a mobile carrier. That 29 December attack on a combined heat and power plant serving around 50,000 residents shut down a steam turbine and the water treatment system, and coincided with coordinated attacks affecting 30 renewable energy facilities and another CHP plant. Investigators initially mistook it for contractor error, and the analysis took over three months.
The pattern for defenders: Polish institutions are being probed and hit across health, justice, transport, and energy, and the highest-yield targets are the shared service providers that aggregate data or connectivity for hundreds or thousands of downstream organisations. One MyDr means thousands of clinics breached at once.
Attribution is, for now, pointed away from a state. Gawkowski said "there is no indication we are dealing with an external attack from Russia or any other country," and reporting indicates he assessed it as very likely the work of cybercriminals. That is a preliminary ministerial assessment, not a forensic conclusion, and it is worth noting Poland has been repeatedly targeted by Russia-linked operators.
The Attack Technique
Not disclosed. No source among those reviewed identifies an initial access vector, a vulnerability, a malware family, or a named threat actor for the MyDr incident. Gawkowski said cybersecurity services were still working to establish how the incident occurred, and that MyDr has been continuously providing authorities with verified information about its response. The attackers have not been identified publicly.
Anyone circulating a specific CVE, ransomware brand, or intrusion chain for this breach at this stage is ahead of the evidence. What is known is behavioural rather than technical: the actors went to a journalist first, led with a proof sample targeting a prominent politician, and, as of MyDr's Wednesday update, had not dumped the data publicly. That sequencing is consistent with an extortion play in its leverage phase rather than a completed leak, though no source reviewed confirms a ransom demand.
The CERT Polska private APN case in the same reporting window is a separate incident with a different victim and is not connected to MyDr. It is included here as sector context, not as the MyDr vector.
What Organizations Should Do
For Polish healthcare providers, and for any organisation that used MyDr as a processor:
- Meet the GDPR clock, and document it. Poland's data protection authority, UODO, has reiterated that the controller must report a personal data breach to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Notification submitted after 72 hours must be accompanied by an explanation of the delay. UODO has stated explicitly that the obligation to notify affected individuals falls on the controllers who used MyDr's services, not on MyDr alone, and that they should do so immediately.
- Write notifications that are actually usable. UODO's guidance is that notices to individuals should describe the nature of the breach and what the person should do. Point Polish residents to the government's Bezpieczne Dane service, where information on the stolen data is to be made available, and tell them to lock their PESEL ("zastrzeż PESEL") as the first action, which was Gawkowski's own top recommendation.
- Warn users about the second-wave scam. Mass breaches are followed by phishing and vishing that impersonates the breached provider or the state. UODO specifically flags the case where an entity demands a copy of an ID document: individuals should ask that entity to state its legal basis for the request. Brief your support staff so they do not become the vector.
- Inventory your processors and their data reach. Identify every third party holding your patients' or customers' identity plus clinical data, confirm what fields each holds, and confirm your contractual breach-notification timelines actually let you meet 72 hours. If you learned about a processor breach from a news site, that pipeline is broken.
- Hunt for bulk-egress patterns, not just malware. A 2 TB extraction is not subtle at the network layer. Alert on anomalous database read volume, off-hours large outbound transfers, new service-account activity, and API calls returning oversized result sets. Retain and centralise logs long enough to reconstruct months of activity; CERT Polska's CHP investigation needed more than three months of analysis to reach a conclusion.
- Reduce internet-facing exposure and validate credentials. Given TechCrunch's reporting on exposed Polish court, hospital, and airport infrastructure, run an external attack surface review against your own ranges, close or authenticate forgotten remote access paths and legacy admin interfaces, enforce MFA on all remote and administrative access, and check that assumed-isolated networks are genuinely isolated.
- Do not treat "no data published yet" as resolution. MyDr's statement that there is no evidence of publication describes a point in time. Plan on the assumption that the data circulates eventually, and build your fraud-monitoring and patient-communication posture accordingly.
Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Security researchers scanned the Polish web and found courts, hospi... | Previously unseen entry vector used to breach Polish energy plant -... | Cyberattack Targets MyDr Healthcare Platform. Authorities Investiga... | Miliony osób mogą dostać powiadomienia. Oto co muszą zrobić po wyci... | Poland hit by theft of 19 million patients’ data from medical platf... | Poland hit by massive healthcare data breach affecting nearly 19 mi... | Medical records of nearly 19 million Poles leaked - Türkiye