Poland's Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski confirmed on Wednesday, 12 August 2026, that data belonging to nearly 19 million Poles was stolen in what he called an "unprecedented" cyberattack on MyDr, one of the country's largest providers of electronic medical documentation software. Speaking after a session of the Joint Cybersecurity Operations Centre, Gawkowski said the stolen database exceeds 2 TB and that the figure was confirmed by the company itself. Figures reported for the scale differ slightly by source: Gawkowski and the state news agency PAP describe "nearly 19 million" people and "19 million records stolen" (via TRT World and Portal Samorządowy), while the purported attackers told Polish security outlet Zaufana Trzecia Strona they hold 18,814,422 unique PESEL numbers (reported by Interia via Europe Says). Poland's population is roughly 37 million, meaning the breach plausibly touches half the country. No attribution has been made, and Gawkowski has said there are currently no indications of a state-sponsored attack by another country.
What Happened
The public timeline starts earlier than the 19 million figure. On Monday, 10 August, Gawkowski posted the first official notice on X that MyDr, a healthcare platform owned by the Docplanner group, had been targeted, and that there were indications of possible unauthorised access to the company's systems. At that stage, as Poland Insight reported citing PAP, there was no confirmed evidence that data had been exfiltrated. MyDr informed its customers, medical facilities and individual doctors, that it had identified possible unauthorised access.
Two days later that position changed materially. At the 12 August press conference, Gawkowski stated that the theft was confirmed by the company and quantified it at roughly 19 million records and more than 2 TB of data. MyDr itself has acknowledged a "data incident." Read together, the sources describe a fast escalation from suspected intrusion to confirmed mass exfiltration inside 48 hours, which is consistent with an incident where the initial access was detected before the scope of staged data theft was understood.
MyDr sits in the software layer beneath the healthcare system rather than being a hospital itself. It supplies practice management and electronic medical documentation software to medical entities, and it interoperates with the widely used booking service ZnanyLekarz, the Polish arm of Docplanner. That architecture is why a single vendor compromise scales to a national-level figure: the records belong to thousands of separate data controllers, not to MyDr.
Anadolu Agency and TRT World both carried the announcement internationally on 13 August, citing broadcaster TVP World, without adding independent technical detail. Treat the international wire coverage as amplification of the ministerial statement, not as separate confirmation.
What Was Taken
The clearest description of content comes from the Polish-language reporting. The stolen set is said to combine PESEL numbers (Poland's national identity number, which encodes date of birth and sex), contact details, and medical data. Gawkowski's phrasing was that the records contain "various types of data that can be linked together," which is the operative risk: identity keys joined to clinical context.
Volume claims:
- Over 2 TB of data, per Gawkowski (PAP, reported by Portal Samorządowy and Europe Says).
- Nearly 19 million affected individuals / 19 million records, per Gawkowski.
- 18,814,422 unique PESEL numbers, per the alleged perpetrators who contacted Zaufana Trzecia Strona. This is an attacker claim relayed by a single reporting chain and should be treated as unverified, although it is close enough to the official figure to be mutually corroborating on order of magnitude.
Krzysztof Kaliński, a cybersecurity specialist at Civitas University speaking to Interia, framed the sensitivity plainly: alongside PESEL and phone numbers there is medical data, opening the door not just to credit fraud but to blackmail, because people have conditions and take medications they may not want disclosed. He also expects resale on criminal markets and loan fraud attempts through non-bank lenders. Those are expert projections, not observed activity.
Ordinary Poles cannot yet check their own exposure. Gawkowski said a procedure has been implemented to migrate the leaked information into the government's Bezpieczne Dane service (bezpiecznedane.gov.pl), where citizens will eventually be able to query whether they are affected.
Why It Matters
This is a third-party risk incident wearing a healthcare costume. The regulator's guidance makes the legal shape explicit: Poland's data protection authority, UODO, stated that the obligation to notify affected individuals rests on the data controllers who used MyDr's services, and that they should do so without delay. Under GDPR Article 33, controllers must report a breach to the supervisory authority without undue delay and where feasible within 72 hours, attaching an explanation if late. In practical terms, thousands of clinics and practices each inherit a notification duty for a breach they did not cause and cannot investigate themselves.
Polish regulators have already been signalling that outsourcing does not outsource liability. In July 2026, UODO president Mirosław Wróblewski issued a formal reprimand to a specialist hospital in Sosnowiec for failing to verify that its processor provided sufficient security guarantees, and for failing to properly assess the risk of processing personal data over email, in a case involving just 224 people. The processor's defence, that it held ISO/IEC 27001 certification and considered its measures adequate, did not shield the controller. Any Polish medical entity now sitting downstream of MyDr should read that decision as the template for how enforcement will run at 19 million scale.
The sector context is also deteriorating. Data from Poland's e-Health Centre, cited in a CSIRT CeZ report, recorded 1,441 cybersecurity incidents affecting healthcare in 2025, more than 60% above the previous year, with online fraud, vulnerable exposed services, and compromised accounts among the most common categories. Separately, on 21 July 2026, PaKK-MED, an association of Polish primary care facilities, was hit by ransomware that took down core IT and forced clinics back onto paper for patient management, scheduling, and record access, with names, PESEL numbers, health records, and staff data at risk. PaKK-MED notified UODO and the prosecutor's office. That is a distinct incident from MyDr with no reported link between the two, but it lands in the same three-week window.
TechCrunch reported on 7 August that security researchers who scanned Polish internet-facing infrastructure found courts, hospitals, and airports exposed to hacking risk. Again, no connection to MyDr has been alleged. The value is as an independent read on national attack surface: the exposure was visible to outside scanners before the two healthcare incidents became public.
The Attack Technique
Unknown, and no source claims otherwise. What the reporting supports:
- Initial characterisation was "possible unauthorised access" to MyDr's systems, later upgraded to confirmed theft of a multi-terabyte dataset.
- The volume and the fact that it resolves to a clean count of unique PESEL numbers point to database or bulk export access rather than opportunistic file scraping, though no source states this and it remains inference.
- The alleged attackers proactively contacted a journalist outlet (Zaufana Trzecia Strona) with a specific record count. That is characteristic of extortion or reputation-driven actors rather than quiet espionage collection, and it is consistent with Gawkowski's statement that there is no current indication of a foreign state actor.
- No ransomware, no ransom demand, and no leak-site posting has been reported for MyDr in these sources. The ransomware detail in this brief belongs to PaKK-MED, a separate victim.
- Polish cybersecurity services are still working to establish how the incident occurred, and the government said it is taking steps to secure all information related to the breach.
Anyone publishing an entry vector for MyDr right now is ahead of the evidence.
What Organizations Should Do
- Inventory your EMR and practice-management vendors, then confirm your controller obligations. If you are a Polish medical entity using MyDr, ZnanyLekarz-linked booking, or any Docplanner-group service, the notification duty is yours per UODO, not the vendor's. Start the Article 33 clock from when you became aware, and document the reasoning if you file late.
- Re-run processor due diligence against the Sosnowiec standard. A vendor's ISO/IEC 27001 certificate did not satisfy UODO as evidence of sufficient guarantees. Demand and retain evidence of actual technical and organisational measures, and record a risk analysis that leads to concrete mitigations, not just a filed document.
- Advise affected individuals to freeze their PESEL immediately. This was Gawkowski's first instruction and UODO's headline guidance. Pair it with caution about giving personal data over the phone or online, and with UODO's specific warning: if a controller demands a copy of an identity document, ask them to state the legal basis.
- Model medical-data extortion, not just credit fraud. The joinability of PESEL plus contact details plus diagnoses and prescriptions enables highly targeted pretexting and blackmail against patients and staff. Brief front-desk and clinical staff that callers may now know a patient's real conditions, and stop treating knowledge of personal details as caller authentication.
- Audit your own internet-facing surface before someone else scans it. The TechCrunch findings on exposed Polish courts, hospitals, and airports, and CSIRT CeZ's tally of vulnerable services among the top incident categories, both point at unmanaged exposure. Enumerate what is reachable from the internet, especially management interfaces and legacy record systems.
- Rehearse the paper fallback. PaKK-MED kept care running by reverting to manual processes after its systems went dark. Confirm that your clinics have current printed schedules, downtime forms, and a defined manual workflow, and that staff have practised it.
- Log and monitor bulk data access. Whatever the vector at MyDr, a multi-terabyte export covering nearly 19 million people should generate alerts. Set thresholds on mass reads and exports from record systems, and make sure someone is watching them outside business hours.
Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Security researchers scanned the Polish web and found courts, hospi... | Medical data breach exposes information of 19 million Poles - TRT W... | Cyberattack Targets MyDr Healthcare Platform. Authorities Investiga... | Ransomware Attack Disrupts Polish Healthcare Network | Miliony osób mogą dostać powiadomienia. Oto co muszą zrobić po wyci... | Wyciekły dane blisko 19 mln Polaków. Gdzie sprawdzić? Jak się zabez... | Kara UODO dla szpitala w Sosnowcu