Poland's Ministry of Digitalisation confirmed on Wednesday 12 August 2026 that MyDr sp. z o.o., a private vendor of electronic medical records software used by roughly 12,000 Polish healthcare facilities, was breached and that data belonging to nearly 19 million citizens was stolen. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history" and said the stolen database exceeds 2 TB. Prime Minister Donald Tusk, speaking the following day, described the techniques as highly sophisticated and the motive as "purely criminal," pointing to an attempted ransom extortion. Gawkowski has stated there are currently no indications the data was stolen by another state. The headline figure is not yet an established fact: the attackers claim 18,814,422 unique PESEL numbers, the government says nearly 19 million records, and MyDr itself says it cannot confirm any quantity or type of data until forensic analysis completes.
What Happened
According to Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office overseeing the case, the perpetrator obtained unauthorised access to MyDr's servers no later than 6 August 2026, by breaking or circumventing IT security measures. The offence as charged carries a penalty of up to three years in prison.
The attackers did not go to MyDr. Cybernews reports they were unable to reach company representatives and instead approached Polish media, including Wyborcza.pl and the IT security news service Zaufana Trzecia Strona (Z3S). Z3S says it was contacted by the alleged perpetrators on Saturday 8 August and published first, at the start of the following week. Notes From Poland dates that first report to Monday; Pollar's timeline lists 11 August for the first investigative actions taken ex officio, so the exact day of the initial publication varies slightly between accounts.
MyDr then confirmed on its own incident page that it had "become the target of an external, deliberate criminal activity involving some of our data." The Ministry of Digitalisation confirmed the attack publicly on 12 August, the CBZC (Central Bureau for Combating Cybercrime) formally opened an investigation the same day, and Tusk and Gawkowski held press conferences on 13 August.
MyDr has been part of the Docplanner group since the acquisition announced on 9 January 2023, the same group behind ZnanyLekarz. Brandsit reports, citing information provided to CRN, that the two systems are separate and do not exchange data, meaning this is not a ZnanyLekarz breach.
The Numbers Do Not Agree
This is the part defenders should hold loosely. Three figures are in circulation and they do not reconcile:
- Claimed by the attackers: 18,814,422 unique PESEL numbers and roughly 2.5 TB of data (per Z3S, relayed by Cybernews and StartupKit). Z3S states it could verify neither the total nor the volume, though it did verify part of the attackers' sample.
- Stated by the government: nearly 19 million records stolen and a database "over 2 TB" in size, per Gawkowski on 12 August. In his public remarks he framed this as company-confirmed: "As confirmed by the company itself, 19 million records were stolen."
- Confirmed by MyDr: nothing. Its incident page, updated at 18:35 CET the same day, says the company cannot confirm the quantity or type of data disclosed and describes the affected data as most likely historical, from 2024 and earlier years, and not covering all MyDr customers and patients.
The two primary-tier statements here, the minister's and the vendor's, were published hours apart and contradict each other on the central fact. StartupKit flags this directly, and it is the honest read: no independently confirmed record count exists as of this writing. Treat "19 million" as a government figure and "18.8 million" as an attacker claim, not as verified counts.
What Was Taken
The data types are more consistent across sources than the volumes are. Per the Ministry of Digitalisation as reported by Pollar, the stolen set includes names, PESEL identification numbers (the Polish national identity number, functionally equivalent to a Social Security number), phone numbers, email addresses, doctors' visit notes, and prescription information. Cybernews adds that MyDr's platform routinely processes appointment records and the general PII that clinical staff handle to deliver care. Brandsit notes MyDr's software is used to maintain electronic medical records, manage appointments, and issue e-prescriptions and e-sick notes.
The proof-of-access sample is the clearest signal of sensitivity. Z3S reported, and Cybernews corroborated, that the attackers supplied journalists with a database screenshot containing the personal data of "one of the most important politicians in Poland," including that person's PESEL number, two phone numbers, and a list of 25 prescriptions issued to them. That is identity data and clinical history joined in a single record.
If the figures hold, roughly half of Poland's population is affected. Critically, many of those people will never have heard of MyDr: as Brandsit points out, patients landed in the database by virtue of their clinic's software choice, not any direct relationship with the vendor.
Why It Matters
This is a supply chain concentration failure, not a hospital breach. One software vendor sitting behind 12,000 facilities produced a single point of compromise with national-scale blast radius. The organisations that lost their patients' data mostly did nothing wrong at the perimeter; they chose a supplier.
The data combination is close to worst case for downstream fraud. PESEL plus phone number plus verified prescription history enables identity theft, and it enables phishing and vishing that is far harder to dismiss than the usual generic lure, because the caller can cite a real medication or a real appointment. Gawkowski's public advice reflects that risk: he urged Poles to use government services to check whether their data is affected and to "lock" their PESEL number to block fraudulent credit and identity use.
The extortion angle matters too. Per Tusk, the evidence points to a ransom attempt against MyDr, and the attackers' escalation to the press after failing to reach the company suggests a pressure campaign rather than a straightforward dump-and-sell.
Context on the trend line: Brandsit notes that reported cybersecurity incidents in Poland rose 144 percent year over year in 2025. And the state-actor question is live in Poland for good reason. SecurityWeek reports that CERT.PL documented a second Sandworm-linked destructive attack on Polish energy infrastructure in December 2025, in which attackers pivoted through a private APN, a vector CERT.PL believes was used here for the first time, after gaining a foothold on an internet-exposed Fortinet VPN and firewall device at a wind farm. That is a separate incident with separate attribution, and both Gawkowski and Tusk have pointed away from a state actor in the MyDr case. It is worth understanding why the assessment had to be made explicitly.
The Attack Technique
The initial access vector has not been disclosed. The only official characterisation is the prosecutor's: unauthorised access to MyDr's servers obtained by breaking or circumventing IT security measures, no later than 6 August 2026. Tusk described "very sophisticated techniques and methods," but no technical detail, malware family, or exploited CVE has been made public by MyDr, CERT.PL, or the CBZC. Cybersecurity services are still working to establish how the incident occurred, per Gawkowski.
No threat actor has been identified. The attackers are unnamed and, per Cybernews and Notes From Poland, unattributed to any known group.
One structural detail is documented and worth noting. StartupKit's analysis observes that MyDr had no supported external channel for reporting a security problem, and that the attackers, unable to reach the company, went to journalists instead. A vulnerability disclosure programme would not have prevented the intrusion. It would have changed who found out first and how long it took, and in this case the company appears to have learned the scope of its own breach through the press.
What Organizations Should Do
- Inventory your healthtech and records-management suppliers by data volume, not by contract value. The vendor holding your full patient population is a tier-one risk regardless of what you pay them. Map which third parties can reach PESEL-equivalent national identifiers joined to clinical data, and treat those systems as crown jewels under someone else's control.
- Stand up a vulnerability disclosure channel and monitor it. A published security.txt and a monitored security@ address cost almost nothing. In this incident, the party with the most urgent information about the breach could not reach the breached company. Do not make the press your detection layer.
- Audit egress and bulk-read patterns on records databases. A 2 TB-plus exfiltration is not subtle at the network layer. Alert on volumetric anomalies in database reads and outbound transfers, not just on authentication events, and confirm you retain logs long enough to reconstruct a window that opened before you noticed it.
- Test the assumption that historical data is low risk. MyDr describes the affected data as most likely from 2024 and earlier. A PESEL number does not expire and a prescription history does not become less sensitive with age. Apply the same controls and retention discipline to archived records that you apply to live ones, and delete what you no longer need.
- Pre-write the identity-fraud playbook for patients. Poland has a national mechanism to lock an identity number; know the equivalent in your jurisdiction before you need it, and be prepared to tell affected people exactly what to do within hours of disclosure rather than days.
- Prepare staff and patients for medically-informed social engineering. Fraud following this breach will cite real medications, real appointments, and real doctors. Update phishing and vishing awareness content accordingly, and establish out-of-band verification for any inbound contact referencing a patient's clinical history.
- Communicate ranges, not headlines, internally. If your organisation is downstream of this incident, brief leadership on the confirmed range (attacker-claimed 18,814,422 records versus a government figure of nearly 19 million versus a vendor confirming no count at all) and revise as forensics land. Precision you do not have will cost you credibility later.
Sources: Medical data breach exposes information of 19 million Poles - TRT W... | Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy F... | Poland hit by theft of 19 million patients’ data from medical platf... | The MyDr data breach may affect 19 million Poles. The data came fro... | European nation rocked by major hacker attack: “largest data leak i... | Polish Healthtech Platform MyDr Hit by Major Data Breach Affecting... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | MyDr Breach: Five Leaks, One Missing Disclosure Channel StartupKit