Poland's Ministry of Digitalization confirmed on Wednesday, 12 August 2026, that MyDr, a private electronic medical records provider serving roughly 12,000 healthcare facilities nationwide, was breached and that data belonging to nearly 19 million citizens was stolen. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history" and said the company itself confirmed the loss of around 19 million records. Prime Minister Donald Tusk said the following day that the motive appears to be "purely criminal" and that indications point to an attempt to extort a ransom. Gawkowski has repeatedly stated there is currently no indication the theft was carried out by another state.
A caveat on sourcing: no primary filing from MyDr, the Polish DPA (UODO), or CERT Polska is available in this source set. Every figure below traces back to government press conferences, prosecutors, the attackers themselves, or MyDr statements quoted secondhand. Treat the numbers as provisional until forensics conclude.
What Happened
MyDr is the technology backbone for thousands of Polish clinics and medical practices, handling electronic medical records, appointment scheduling, e-prescriptions and e-sick notes. As Brandsit notes, that means many patients are in the MyDr database without ever having heard of the brand, having only visited their own clinic. MyDr has been part of the Docplanner group since 2023, the same group that owns ZnanyLekarz; Brandsit reports, citing information given to CRN, that the two systems are separate and do not exchange data, so a ZnanyLekarz compromise should not be assumed.
The public timeline starts with the attackers, not the victim. Notes From Poland reports the incident was first surfaced on Monday by Zaufana Trzecia Strona, a Polish IT security news service, which said it had been contacted on Saturday by the alleged perpetrators claiming access to data on around 18.8 million people. Cybernews adds that the attackers apparently could not reach MyDr representatives and went to the press instead, and that per Wyborcza they approached more than one outlet. Shortly afterward, MyDr confirmed it had "become the target of an external, deliberate criminal activity involving some of our data."
Accounts differ on when the intrusion actually occurred. Warsaw district prosecutor's office spokesperson Piotr Antoni Skiba, cited by Pollar, states the perpetrator gained unauthorized access to MyDr's servers no later than 6 August 2026 by breaking or circumventing IT security measures. TVP World, by contrast, describes the breach as having "took place on Wednesday," which matches the date of public disclosure rather than intrusion. The prosecutor's date is the more load-bearing of the two. Pollar's own timeline is also internally inconsistent, labelling 11 August as "Monday" when 12 August is established as Wednesday. The safest reading: intrusion on or before 6 August, attacker outreach to media around 8 August, first reporting 10 to 11 August, government confirmation and CBZC investigation on 12 August, ministerial and prime ministerial press conferences on 13 August.
What Was Taken
Record counts vary by source and by who is doing the counting. Gawkowski and the Ministry of Digitalization put it at nearly 19 million records confirmed by MyDr, a figure echoed by TRT World, EU Startups News, Brandsit, Notes From Poland and Pollar. The attackers themselves claimed 18.8 million people to Zaufana Trzecia Strona and to Cybernews' reporting. Cybernews frames it as "over 18 million," roughly half of Poland's population. The 19 million figure counts records; the 18.8 million figure counts individuals, which may explain part of the gap rather than a genuine dispute.
Database size also differs by source. Gawkowski put the stolen database at over 2 TB, per Brandsit and Pollar. The attackers told journalists they held over 2.5 TB.
On content, Pollar itemises names, PESEL national identification numbers, phone numbers, email addresses, doctors' visit notes and prescription information. Notes From Poland adds diagnoses. Cybernews lists PESEL, prescriptions, appointment records and general PII handled by medical staff. As proof of access, the attackers showed journalists the record of "one of the most important politicians in Poland," including that person's PESEL, two phone numbers and a list of 25 prescriptions.
MyDr's own position is more conservative than the government's. Per its breach notice as quoted by Cybernews, the company says the affected information likely dates to 2024 and earlier, does not cover all MyDr customers and patients, and that "we are currently unable to confirm the amount and type of data that was exposed. We will do so once the forensic analysis is completed."
Gawkowski said as of his 13 August remarks the stolen records had not appeared in the public domain or been offered for sale, that steps were being taken to secure the data and prevent its sale, but that no guarantee could be given it would not eventually leak.
Why It Matters
This is a supplier compromise, not a hospital compromise. One vendor sitting under 12,000 facilities converted a single intrusion into a national-scale health data loss. Every healthcare system that has consolidated EMR, e-prescribing and scheduling into a handful of platform providers carries the same shape of risk, and most have not modelled their vendor as a single point of failure for half their population.
The data class makes it worse. PESEL is Poland's national identity number and is not rotatable. Paired with prescription histories and diagnoses, it enables identity fraud, loan fraud, and highly credible medical-themed phishing, the specific downstream risk Brandsit flags. It also enables targeted coercion, which is why Poland's domestic intelligence service (ABW) proactively contacted prominent public figures whose data was affected to reduce blackmail exposure.
The national context matters too. Brandsit reports that cybersecurity incidents reported in Poland rose 144 percent year over year in 2025. A week before the MyDr disclosure, at Def Con on 7 August, Polish researchers Robert Kruczek and Kamil Szczurowski presented findings from scanning their country's public web: more than 10,000 affected public entities across 250,000 websites with security flaws, including hospitals, airports and government offices. TechCrunch reports they found critical flaws in the widely used Pad CMS that gave passwordless access to over 300 public websites, with the vendor declining to patch because the product was end of life, and a separate bug reaching roughly 245 courts, about two thirds of Poland's judiciary. The researchers described vendors treating bug reports as inconveniences, and noted the absence of bug bounties and coordinated disclosure channels. That research targets a different set of systems than MyDr and should not be read as the cause of this breach, but it describes the ecosystem this breach happened inside.
The Attack Technique
Little has been published on mechanics. Tusk described "very sophisticated techniques and methods." Gawkowski said the vulnerability exploited by the attackers has since been identified and patched, without naming it. Prosecutor Skiba's charge framing is that the perpetrator "gained unauthorized access to MyDr's servers no later than August 6, 2026, by breaking or circumventing IT security measures," an offence carrying up to three years in prison.
Beyond that, no CVE, no initial access vector, no malware family, no named group. The attackers are unidentified. Gawkowski said state security services are tracking the group responsible and that there is currently no evidence of foreign involvement. The extortion pattern is exfiltration-and-leak-threat rather than confirmed encryption; no source describes ransomware deployment or service disruption at MyDr, and no leak site posting has been reported. The decision to contact journalists after failing to reach the company is consistent with a pressure play rather than a quiet data sale.
The Polish government's answer has been categorical. "The ministry and state services do not negotiate with hackers. We hunt criminals down; we do not strike deals with them," Gawkowski said, adding: "Nobody will negotiate with anyone. Nobody will give in to any blackmail."
What Organizations Should Do
- Inventory your healthcare vendor blast radius. Identify every third party that holds patient records on your behalf, and for each one determine how many patients would be exposed by a full compromise of that vendor. If any single supplier accounts for a majority of your patient population, that is a board-level concentration risk, not an IT issue.
- Contract for forensic and notification obligations up front. MyDr could not state the volume or type of exposed data days into public disclosure. Require vendors to commit to notification timelines, log retention sufficient for reconstruction, and your right to receive forensic findings directly rather than through press conferences.
- Hunt for pre-disclosure access. Prosecutors date access to no later than 6 August, but the ceiling, not the floor, is established. Review authentication logs, service account usage, API call volumes and egress patterns across integrated EMR systems back at least 90 days, focusing on bulk read operations and unusual data transfer volumes.
- Audit end-of-life software in your public-facing estate. The Pad CMS finding is the archetype: unsupported software the vendor will not patch, reachable from the internet, sitting under hundreds of public sites. Enumerate every internet-facing component, flag anything past vendor support, and treat "no longer supported" as an active vulnerability rather than a procurement footnote.
- Establish a working vulnerability disclosure channel. The researchers' central complaint was that reports had nowhere to land and were dismissed when they did. Publish a security.txt, staff an intake address, and define an SLA for triage. This is the cheapest control on this list.
- Prepare identity-protection guidance before you need it. Poland's response leaned on citizens checking exposure through government services and "locking" their PESEL to block fraudulent credit. Know in advance what equivalent freeze, alert and verification mechanisms exist in your jurisdiction, and have the notification copy drafted.
- Raise your identity-verification bar against medical-context phishing. Attackers holding real prescription and diagnosis details can construct pretexts that defeat standard "confirm your date of birth" checks. Move clinical and billing support staff onto verification factors that stolen medical records do not contain.
Sources: Medical data breach exposes information of 19 million Poles - TRT W... | Security researchers scanned the Polish web and found courts, hospi... | Ransom likely motive in mass breach of Polish medical data | Polish Healthtech Platform MyDr Hit by Major Data Breach Affecting... | European nation rocked by major hacker attack: “largest data leak i... | The MyDr data breach may affect 19 million Poles. The data came fro... | Poland hit by theft of 19 million patients' data from medical ... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles...