SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-HEALTH-PLAT 2026-08-13

MyDr: Mass Data Theft From Poland's Medical Records Platform

"Polish authorities and the affected vendor have disclosed one of the largest data breaches in the country's history: a criminal intrusion into MyDr, a healthcare software provider whose systems handle electronic…"

Polish authorities and the affected vendor have disclosed one of the largest data breaches in the country's history: a criminal intrusion into MyDr, a healthcare software provider whose systems handle electronic prescriptions, visit histories and sick-leave documents for thousands of medical facilities. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski announced the incident on Wednesday 12 August following a session of the Joint Cybersecurity Operations Center, calling it "an unprecedented incident of great magnitude in the country's IT security" and "one of the largest incidents in Poland's history." Reported scale ranges from 18,814,422 unique PESEL national identity numbers claimed by the attackers themselves (via Polish security outlet Zaufana Trzecia Strona, as relayed by Notes from Poland and Poland Daily 24) to the "19 million records" Gawkowski said the company itself had confirmed stolen. Pollar reports the stolen database exceeds 2 TB. Note that none of the available reporting is first-party: no direct MyDr filing, CERT Polska advisory or UODO regulator notice is in this source set, and the figures below are attributed accordingly.

What Happened

The public timeline begins outside official channels. According to Notes from Poland's account of Zaufana Trzecia Strona's reporting, the alleged perpetrators contacted the Polish security outlet on Saturday 8 August, claiming access to the data of roughly 18.8 million people and supplying a screenshot from the compromised database showing the personal data of "one of the most important politicians in Poland." Z3S published on Monday 10 August. The same day, Gawkowski posted the first official acknowledgement on X, saying services had been notified and were working to establish the circumstances of the attack while supporting the company in securing its IT infrastructure. MyDr separately told its customers, medical facilities and doctors, that it had identified possible unauthorised access.

The official framing hardened over roughly 72 hours, and the sources capture that shift rather than a single consistent account. Poland Insight, reporting the early state of play via PAP, recorded only "indications of potentially unauthorised access" with no confirmation that data had been exfiltrated. Poland Daily 24, as carried by Anadolu Agency and europesays, has Gawkowski simultaneously stating that "as confirmed by the company itself, 19 million records were stolen, containing various types of data that can be linked together," while cautioning in written comments that "at this stage of the investigation, it is not yet possible to conclusively confirm that a data breach occurred. However, there are many indications that an unauthorized person may have gained access to the data." Those two statements are difficult to reconcile, and readers should treat the theft as company-acknowledged but not yet forensically closed.

At a Thursday 13 August press conference at the Command of the Cyber Defense Forces Component in Legionowo, Gawkowski said the stolen data is not currently in the public space, is not being offered for sale, and is not part of any extortion scheme that services can identify. MyDr issued a statement the same day characterising the stolen data as historical, dating from 2024 and earlier, per Pollar's timeline. The company had earlier confirmed it had "become the target of an external, deliberate criminal activity involving some of our data," and said in a Wednesday update that there was no evidence the data had been published anywhere.

What Was Taken

The stolen material is clinical, not merely administrative, which is what separates this from a routine identity-data leak. Across the reporting, the dataset includes:

Volume estimates differ by measure rather than contradicting outright: 18.8M PESELs (attacker claim), 19M records (Gawkowski citing MyDr), and a database exceeding 2 TB (Pollar). "Records" and "unique individuals" are not the same unit, and no source in this set reconciles them.

Blast radius is wide. DistantNews puts the number of affected healthcare centres at approximately 12,000, citing Gawkowski, and describes MyDr's services as used by nearly all public and private healthcare facilities in Poland. Pollar reports that Medicover confirmed MyDr software is used by its dental clinics and has begun internal analysis, and that Ministry of National Defence employees received an email warning about a potential data breach. MyDr is owned by the Docplanner group and shares a corporate group with the consumer-facing ZnanyLekarz platform.

Why It Matters

This is a supply-chain compromise wearing a healthcare costume. The attackers did not breach 12,000 clinics; they breached the one vendor those clinics all depend on. Concentration of clinical data in a single national-scale software provider converts one intrusion into a country-level exposure event, and no individual hospital's security posture could have prevented it.

Medical data does not expire the way payment data does. A leaked card is reissued in days. A diagnosis, a prescription history, or a psychiatric referral is permanent leverage, and PESEL numbers are static national identifiers that cannot be rotated. MyDr's characterisation of the data as "historical, from 2024 and earlier" is a mitigation for regulatory purposes, not for the affected patients. Poland's government has stood up bezpiecznedane.gov.pl for citizens to check exposure and is urging PESEL locks through mObywatel; both services were reported overloaded by demand, which is itself a useful capacity lesson for any government running breach-response infrastructure.

The incident lands in an already deteriorating sector. Poland Insight cites CSIRT CeZ data showing 1,441 cybersecurity incidents affecting Polish healthcare in 2025, more than 60% above the prior year, with online fraud, vulnerable exposed services and compromised accounts among the most common categories. TechCrunch reported on 7 August, days before this disclosure, on security researchers who scanned Polish internet-facing infrastructure and found courts, hospitals and airports at risk of compromise. The MyDr breach reads less like an outlier than like the predicted outcome.

The Attack Technique

Root cause is not established, and officials have been unusually direct about that. Gawkowski said at Legionowo that nothing indicates an entity from outside Poland participated, and specifically that "there is no indication we are dealing with an external attack from Russia or any other country," a notable statement given Poland's sustained targeting by Russian state-linked actors. Notes from Poland reports Gawkowski assessing it as "very likely" the work of cybercriminals rather than a state operation. The government has said the matter is referred to the Prosecutor's Office, that intelligence services are investigating, and, per DistantNews, that it "will not yield to any blackmail."

Two attribution threads should be treated as low confidence. Pollar reports Deputy Minister Gramatyka saying human error may be the source and that the attacker was possibly operating from the India region. Pollar also reports that the ABW internal security agency "secured key persons." Both claims appear in a single OTHER-tier source and neither has been corroborated elsewhere in this set. No vulnerability, initial access vector, dwell time, or exfiltration method has been published by anyone. The attackers' choice to contact a security journalist with a proof-of-access screenshot, rather than post to a leak site, is consistent with either an extortion attempt in progress or a pressure play that had not yet found a buyer.

What Organizations Should Do

  1. Inventory your clinical software supply chain by data access, not by contract value. The question is not which vendors you pay the most, but which ones hold copies of your patient records. Any vendor with a replicated clinical dataset is a single point of national-scale failure, exactly as MyDr appears to have been for roughly 12,000 facilities.
  2. Demand exfiltration-capable telemetry from vendors, contractually. MyDr's public position moved from "possible unauthorised access" to a company-confirmed theft of millions of records inside three days. That gap is a detection and egress-monitoring gap. Require vendors to evidence outbound data volume monitoring and to commit to disclosure timelines.
  3. Purge historical data you are not required to hold. The stolen set is reportedly 2024 and earlier. Retention beyond legal minimums is pure liability with no operational upside, and 2 TB of legacy clinical records is a breach waiting for a vector.
  4. Segment and rate-limit bulk read access to patient databases. Nineteen million linked records leaving an environment implies an account or interface that could query at scale. Cap query volume per credential, alert on anomalous bulk reads, and separate reporting or analytics access from production clinical access.
  5. Treat national identifiers as compromised by default in your fraud logic. PESEL, and its equivalents elsewhere, cannot be reset. Any authentication or account-recovery flow that treats a national ID as a secret is already broken. Push affected populations toward identity-lock mechanisms where they exist.
  6. Rehearse the disclosure and citizen-facing surge. Poland's official data-check portals were overloaded on day one. If your breach plan routes millions of people to a lookup page, load-test that page before you need it, and pre-write the customer notification.
  7. Assume phishing follows the leak. Prescription and appointment data makes for extremely convincing lures. Brief staff and patients that attackers now hold context specific enough to defeat generic "does this look suspicious?" heuristics.

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Security researchers scanned the Polish web and found courts, hospi... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | Cyberattack Targets MyDr Healthcare Platform. Authorities Investiga... | Cyberattack Exposes Data of Nearly 19 Million Poles DistantNews | Poland hit by theft of 19 million patients’ data from medical platf... | Poland hit by massive healthcare data breach affecting nearly 19 mi... | Medical records of nearly 19 million Poles leaked - Türkiye