SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-MEDICAL-PLA 2026-08-13

MyDr: Nationwide Medical Records Breach Hits Nearly 19 Million Poles

"Poland is dealing with what its own digitalisation ministry calls an unprecedented cybersecurity incident. Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski confirmed on Wednesday 12 August 2026…"

Poland is dealing with what its own digitalisation ministry calls an unprecedented cybersecurity incident. Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski confirmed on Wednesday 12 August 2026 that attackers stole roughly 19 million records, amounting to more than 2 terabytes of data, from MyDr, one of Poland's largest providers of electronic medical documentation (EDM) systems. MyDr belongs to the Docplanner group, the same corporate family as the consumer booking platform ZnanyLekarz, and its software is used by around 12,000 healthcare facilities nationwide. Gawkowski stated at a press conference following a session of the Joint Cybersecurity Operations Centre that the theft was confirmed by the company itself. A caveat worth stating up front: no vendor advisory, regulator decision, or national CERT bulletin is among the sources reviewed here. Every figure below traces back to ministerial statements, a company statement, or attacker claims as relayed through press reporting.

What Happened

The public account moved in stages over four days, and the earlier reporting reads very differently from the later reporting.

The first official signal came on Monday 10 August, when Gawkowski posted on X that services had been notified of a cybersecurity incident in MyDr's systems and data. Poland Insight, citing the Polish Press Agency, reported at that point only that there were indications of possible unauthorised access and that there was no confirmation any patient or customer data had been exfiltrated. MyDr's customers, meaning the medical facilities and doctors who use the platform, were told the company had identified possible unauthorised access.

Poland Daily 24 reported the intermediate stage, quoting Gawkowski as saying that at that stage of the investigation it was "not yet possible to conclusively confirm that a data breach occurred," while adding that "there are many indications that an unauthorized person may have gained access to the data." That same reporting notes the alleged perpetrators had contacted journalists at the Polish security site Zaufana Trzecia Strona, claiming to hold patient data from numerous Polish clinics.

By Wednesday 12 August the position had hardened. Speaking after the Joint Cybersecurity Operations Centre convened, Gawkowski said flatly, per RMF24, that 19 million records were stolen from the company and that the company itself confirmed this. He described the stolen database as exceeding 2 TB. Pollar reports that Gawkowski said the software vulnerability had been identified and sealed and that affected systems were running normally and safely. Portal Samorządowy reports MyDr's own line that its systems are currently fully operational and secure.

On Thursday 13 August, per Pollar's timeline, Gawkowski said there was no indication of a foreign actor and that the full investigation will take weeks. Pollar also records that MyDr confirmed the breach in a statement and characterised the affected data as historical, dating from 2024 or earlier. That characterisation comes from the company and has not been independently corroborated in the material reviewed here. Treat it as a claim, not a finding.

So the honest summary of the sequence is: possible unauthorised access on 10 August, unconfirmed but heavily indicated on 11 August, confirmed theft of 19 million records on 12 August, with attribution still open on 13 August.

What Was Taken

Figures differ depending on who is counting and what they are counting, and the difference matters.

On data types, Pollar lists PESEL national identification numbers, email addresses, phone numbers, login credentials, and medical information including visit histories, prescribed medications and prescriptions. RMF24 quotes Gawkowski describing the compromised system as holding information on prescriptions, booked appointments, prescribed medicines and documents presented to a doctor, which he summarised as "a large package of sensitive data concerning people using primary healthcare." DistantNews adds fiscal information to the list and mentions work leave documentation; that additional category appears in only one source and should be treated as unconfirmed.

For scale context on the underlying data flow, Pollar reports MyDr's platform handles roughly 3 million visits and 2.7 million prescriptions per month across those 12,000 facilities.

The combination is the worst-case shape for a health data breach: a permanent national identifier (PESEL cannot be rotated), direct contact channels, credentials, and clinical detail that supports highly convincing targeted fraud. Gawkowski specifically flagged, per RMF24, that the records involve different data types that can be correlated with one another.

Why It Matters

This is a supplier compromise, not a hospital compromise. One EDM vendor sat upstream of 12,000 facilities, and a single failure there produced a national-scale exposure that no individual clinic could have prevented through its own controls. Any defender running a healthcare estate should read this as a concentration-risk event first and a Poland event second.

The regulatory mechanics show the second-order problem clearly. Portal Samorządowy reports that Poland's data protection authority, UODO, has stated the obligation to notify affected individuals rests with the data controllers who used MyDr's services, meaning the individual clinics and practices, not solely with MyDr. MyDr for its part says everyone affected will be notified. That means thousands of small healthcare organisations, many with no dedicated security or privacy function, now carry a GDPR notification duty for a breach that happened in someone else's infrastructure. UODO also restated the standard GDPR requirement to report a personal data breach to the supervisory authority without undue delay and no later than 72 hours after becoming aware of it.

The incident also lands in a well-documented pattern. Poland Insight cites CSIRT CeZ data from the country's e-Health Centre showing 1,441 cybersecurity incidents affecting the healthcare sector in 2025, more than 60 percent above the prior year, with online fraud, vulnerable services and compromised accounts among the most common categories. TechCrunch separately reported on 7 August, five days before the MyDr confirmation, that researchers Robert Kruczek and Kamil Szczurowski presented findings at Def Con from a scan of Poland's public web: more than 10,000 affected public entities and 250,000 websites with security flaws, including hospitals, airports and government offices. Their findings included critical vulnerabilities in the Pad CMS content management system that gave passwordless access to over 300 public sites, unpatched because the software had reached end of life, and a bug reaching roughly 245 courts, about two-thirds of Poland's judiciary. They also described vendors treating vulnerability reports as inconveniences. There is no evidence linking that research to the MyDr breach, and none is claimed here. What it establishes is the ambient condition: an under-resourced public sector software supply chain with weak disclosure pathways, in a country already absorbing suspected Russian intrusions against energy and water utilities.

The Attack Technique

The initial access vector has not been disclosed, and the government has been explicit that it does not yet know.

What is on the record: Gawkowski said, per Pollar, that a software vulnerability had been identified and sealed and that systems returned to safe, normal operation. That points to an exploited flaw in MyDr's own application or infrastructure rather than, for example, a ransomware deployment. Notably, no source describes encryption, service disruption or downtime; RMF24 reports healthcare facilities continued operating normally throughout, which is consistent with a pure data-theft operation.

RMF24 reports that Gawkowski declined to say whether patient data had been inadequately protected, and floated the range of possibilities openly, including human error, a system fault, or an act of sabotage. On attribution, Pollar records his 13 August statement that there is no indication of a foreign actor, which cuts against the state-sponsored reading that Poland's recent threat environment might otherwise invite. DistantNews reports the origin of the attack remains unknown, that the matter has been referred to the Prosecutor's Office, and that intelligence services are investigating, quoting Gawkowski's position that the government "will not yield to any blackmail." That last remark is the only public hint of an extortion element, and it is indirect. RMF24 notes the Central Bureau for Combating Cybercrime (CBZC) is also on the case, alongside coordination with special services coordinator Tomasz Siemoniak, Health Minister Jolanta Sobierańska-Grenda, and UODO president Mirosław Wróblewski.

The attackers' engagement with Zaufana Trzecia Strona journalists, per Poland Daily 24, is behaviourally consistent with a financially motivated crew building public pressure or credibility ahead of a sale or leak. That is an inference, not a confirmed assessment.

What Organizations Should Do

  1. Inventory your clinical software suppliers and map the blast radius of each. The question this incident poses is not whether your own perimeter holds, but how many patient records a single vendor holds on your behalf and what happens when that vendor is breached. Document which supplier holds which data categories, and confirm in writing who notifies patients if that supplier is compromised.
  2. Confirm your controller obligations now, not after the notice arrives. If UODO's position in this case is a guide, the notification duty may sit with you rather than the vendor. Pre-draft the patient notification template, confirm the 72 hour supervisory notification path, and identify who signs off, before you need any of it.
  3. Treat vendor-side credential theft as your credential problem. Login credentials were among the exposed categories reported by Pollar. Force resets for any staff or facility accounts on the affected platform, enforce phishing-resistant MFA on clinical systems, and hunt for reuse of those credentials against your own SSO, VPN and email.
  4. Prepare for the fraud wave, not just the breach. Stolen visit histories and prescription records enable pretexting calls that sound authentically clinical. Brief front-desk and call-centre staff that callers may cite real appointment and medication details, and set a policy that identity is never verified using data the attacker plausibly holds.
  5. Advise affected individuals on the concrete Polish remedies. Gawkowski's first instruction, per RMF24 and Portal Samorządowy, is to place a restriction on your PESEL number, via the mObywatel app or at a local council office. The government's lookup service is bezpiecznedane.gov.pl, though Pollar's timeline notes the stolen data had not yet been loaded there as of 13 August. UODO additionally advises caution when giving personal data over the internet or phone, and specifically warns that if any organisation demands a copy of an ID document, you should ask them to state the legal basis.
  6. Audit for end-of-life and unsupported software across public-facing estate. The Def Con research reported by TechCrunch found over 300 public websites accessible without a password on a CMS the developer would not patch because it was out of support. Unsupported software in a regulated environment is an accepted breach, not a deferred risk. Pair that with a published vulnerability disclosure channel so researchers can reach you before attackers do.

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Security researchers scanned the Polish web and found courts, hospi... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | Hackers claim to have stolen data of nearly 19 million Polish patients | Cyberattack Targets MyDr Healthcare Platform. Authorities Investiga... | Ogromny wyciek danych z MyDr. Chodzi o nawet 19 mln osób | Cyberattack Exposes Data of Nearly 19 Million Poles DistantNews | Miliony osób mogą dostać powiadomienia. Oto co muszą zrobić po wyci...