SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-HEALTH-RECO 2026-08-13

MyDr: Medical Data on Nearly 19 Million Poles Stolen in Extortion Attack

"Poland's Ministry of Digitalization confirmed on Wednesday, August 12, that a cyberattack on MyDr, a private electronic medical records provider, resulted in the theft of personal and health data belonging to close to…"

Poland's Ministry of Digitalization confirmed on Wednesday, August 12, that a cyberattack on MyDr, a private electronic medical records provider, resulted in the theft of personal and health data belonging to close to 19 million citizens. Figures reported for the affected population differ slightly by source: the attackers themselves claimed roughly 18.8 million people in their outreach to the Polish security outlet Zaufana Trzecia Strona (per Notes From Poland), while government statements and subsequent coverage consistently cite "nearly 19 million." Rzeczpospolita and Pollar both report the stolen dataset exceeds 2 terabytes. Digital Affairs Minister Krzysztof Gawkowski called it "an unprecedented incident of great magnitude in the country's IT security," and Prime Minister Donald Tusk described the intrusion as technically sophisticated with a "purely criminal" extortion motive. In a country of roughly 38 million people, a breach at this scale touches around half the population.

What Happened

The timeline that emerges across sources runs roughly as follows. According to Warsaw district prosecutor's office spokesperson Piotr Antoni Skiba, cited by Pollar, the perpetrator gained unauthorized access to MyDr's servers no later than August 6, 2026, by breaking or circumventing IT security controls. On Monday, August 10, Gawkowski published the first official acknowledgement on X, stating that services had been notified and were working to establish the circumstances of the attack while supporting the company in securing its infrastructure. At that early stage, as Poland Insight reported, MyDr's customers were told the company had identified possible unauthorized access, and there was no confirmed evidence that data had been exfiltrated.

That posture did not hold. Zaufana Trzecia Strona reported on Monday that it had been contacted the previous Saturday by the alleged perpetrators, who claimed to hold the data of around 18.8 million people and who supplied a screenshot from the compromised database showing the personal data of, in the outlet's words, "one of the most important politicians in Poland." Pollar reports that a portion of the stolen data was sent directly to the outlet's editorial team. MyDr then confirmed it had "become the target of an external, deliberate criminal activity involving some of our data."

By Wednesday, August 12, the Ministry of Digitalization had confirmed the attack and Poland's cybercrime bureau CBZC had formally opened an investigation. Tusk and Gawkowski held press conferences on Thursday, August 13. The evolution from "possible unauthorized access, no confirmed exfiltration" to confirmed mass theft inside 48 hours is worth flagging: early vendor statements in this incident understated what had happened, and defenders reading initial disclosures should treat them as a floor rather than a ceiling.

Accounts do converge on one point of relative good news. Gawkowski said on Thursday that the stolen data has not surfaced in the public domain, and MyDr's Wednesday update stated that, at the time of writing, there was no evidence the data had been published. Poland has ruled out any engagement with the attackers, with Gawkowski stating flatly that the government does "not negotiate with hackers" and "will not yield to any blackmail."

What Was Taken

MyDr supplies electronic medical records software to approximately 12,000 healthcare facilities across Poland, covering, per Gawkowski's characterization relayed by ABC Color, nearly all public and private healthcare providers in the country. The platform processes electronic prescriptions, medical histories, and sick leave documentation.

The stolen dataset, reported at over 2 terabytes, includes:

This is close to a worst-case combination. PESEL is Poland's universal national identifier and is used across banking, credit, and government services; pairing it with contact details gives an attacker everything needed for identity fraud at scale. Layering diagnoses and prescription data on top converts a financial fraud dataset into a coercion dataset. Health records do not rotate. A leaked password is replaced in minutes; a leaked HIV status, psychiatric diagnosis, or pregnancy termination record is permanent leverage, and the screenshot the attackers sent to Zaufana Trzecia Strona featuring a senior Polish politician makes the targeting potential explicit rather than theoretical.

Poland Insight reports that MyDr is owned by the Docplanner group. That ownership detail appears in a single source and has not been corroborated elsewhere in the material reviewed here; treat it as unconfirmed pending a company statement.

Why It Matters

The strategic lesson is concentration risk in the healthcare supply chain. No hospital was breached. One software vendor was, and the blast radius covered 12,000 facilities and half a nation's population. Healthcare providers have spent a decade hardening their own perimeters while outsourcing the actual patient record store to a handful of platform vendors, and the aggregate dataset those vendors accumulate is a far richer target than any individual clinic's. The security posture of the entire Polish outpatient system was, functionally, the security posture of MyDr.

The incident lands in a sector already trending badly. Poland's e-Health Centre recorded 1,441 cybersecurity incidents affecting healthcare in 2025 per a CSIRT CeZ report cited by Poland Insight, more than 60% above the prior year, with online fraud, vulnerable services, and compromised accounts among the most common categories. Separately, TechCrunch reported on August 7, days before this breach became public, that security researchers scanning Polish internet-facing infrastructure had found courts, hospitals, and airports exposed to attack. The MyDr compromise is the predictable output of that environment, not an outlier within it.

There is a second-order failure worth noting for anyone drafting an incident response plan. The government stood up bezpiecznedane.gov.pl for citizens to check exposure, and Rzeczpospolita reported the site was unavailable, most likely under the weight of concurrent traffic from millions of anxious users. Breach notification infrastructure that collapses at the moment of disclosure amplifies harm: it pushes victims toward unofficial channels and creates a ready-made lure for phishing sites impersonating the real checker. Capacity-test your victim notification portal against your worst-case affected population, not your average day.

The Attack Technique

The specific initial access vector has not been disclosed. What is on the record is the prosecutor's formal characterization, via Pollar: the perpetrator obtained unauthorized access to MyDr's servers no later than August 6, 2026, by breaking or circumventing IT security measures, an offense carrying up to three years' imprisonment under Polish law. Tusk described "very sophisticated techniques and methods," though that assessment comes from a political press conference rather than a technical postmortem and should be weighted accordingly.

Attribution is open. The attackers have not been identified, and no ransomware brand or extortion group has been named in any of the available reporting. The behavioral fingerprint is consistent with a data-theft extortion operation rather than an encryption-based ransomware event: bulk exfiltration, direct contact with a journalist as leverage, inclusion of a high-profile individual's record as proof and pressure, and no reported service disruption. Gawkowski has stated the affected systems are now secured and operating normally. Nothing in the sourcing supports a state-sponsored reading, and Tusk's own assessment points the opposite direction, toward ransom.

What Organizations Should Do

  1. Inventory your healthcare data processors and demand their controls in writing. If a single vendor holds records for your entire patient population, that vendor's authentication model, egress monitoring, and log retention are your controls. Poland's UODO has already reminded administrators who used MyDr services of their notification obligations; know which of your processors would trigger the same duty for you.
  2. Instrument for bulk egress, not just intrusion. Two terabytes left this environment without triggering an intervention. Alert on anomalous database read volume, off-hours bulk queries, and outbound transfers exceeding a baseline per service account. Exfiltration detection is the control that would have changed this outcome; perimeter prevention is not.
  3. Segment and tokenize national identifiers. PESEL, SSN, and equivalents should not sit in plaintext beside clinical notes in a single queryable store. Separate identity data from health data with distinct credentials and encryption keys so one compromised path does not yield a fraud-ready and coercion-ready dataset in one pull.
  4. Load-test your breach notification path before you need it. Provision the victim-checking portal for peak concurrent load equal to your full affected population, put it behind a CDN, and pre-register the domain. Also pre-write the anti-phishing advisory, because impersonation sites will follow within hours.
  5. Treat first-day vendor statements as provisional. MyDr moved from "possible unauthorized access, no confirmed exfiltration" to confirmed theft of 19 million records in roughly 48 hours. Build your own exposure assessment from your data flows rather than waiting for the vendor's number to stabilize.
  6. Give affected individuals a concrete action, immediately. Poland's guidance was specific and useful: reserve or lock your PESEL via the mObywatel app or at a local office to block credit and identity fraud. Identify the equivalent control in your jurisdiction now, and name it in your notification instead of offering generic vigilance advice.

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Security researchers scanned the Polish web and found courts, hospi... | Poland hit by theft of 19 million patients' data from medical ... | Poles' stolen medical data 'not made public,' gov't says | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | Cyberattack Exposes Data of Nearly 19 Million Poles DistantNews | Data Leak Exposes 19 Million Poles; Government Website Fails Dista... | Cyberattack Targets MyDr Healthcare Platform. Authorities Investiga...