SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-MEDICAL-REC 2026-08-15

MyDr: Nearly 19 Million Polish Patient Records Stolen in Suspected Extortion Breach

"Poland's Ministry of Digitalisation confirmed on 12 August 2026 that MyDr, a private electronic medical records provider serving thousands of clinics nationwide, suffered a cyberattack exposing the personal and health…"

Poland's Ministry of Digitalisation confirmed on 12 August 2026 that MyDr, a private electronic medical records provider serving thousands of clinics nationwide, suffered a cyberattack exposing the personal and health data of close to 19 million people. Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history," a characterisation echoed across all eight sources reviewed. Figures for the victim count differ slightly by origin: the attackers themselves told the Polish security outlet Zaufana Trzecia Strona they held data on "over 18.8 million unique PESEL numbers" (per thepublic.info and Notes From Poland), while Gawkowski and the Ministry describe "nearly 19 million" people, and Brandsit reports the company itself confirmed the loss of "around 19 million records." The stolen dataset is consistently described as exceeding 2 terabytes. Prime Minister Donald Tusk said on 13 August that the motive appeared to be a criminal attempt to extort a ransom from MyDr.

What Happened

MyDr supplies electronic medical records, appointment management, e-prescription and e-sick-note software to Polish healthcare providers. Source figures for its footprint cluster tightly: Pollar and Brandsit both put it at roughly 12,000 healthcare facilities, while thepublic.info, citing RMF24, describes "thousands of doctors' surgeries and clinics" processing around 3 million appointments and 2.7 million prescriptions per month. A LinkedIn commenter on the data protection authority's own post noted that some 47,000 doctors were working with MyDr as of three years ago, an unverified figure but one that gives a sense of the downstream controller population. Since 2023 MyDr has been part of the Docplanner group, which also owns ZnanyLekarz; Brandsit reports, citing information given to CRN, that the two systems are separate and do not exchange data, so ZnanyLekarz records are not implicated.

Accounts of the timeline do not fully agree. The Warsaw district prosecutor's office, through spokesperson Piotr Antoni Skiba, states that the perpetrator gained unauthorised access to MyDr's servers "no later than 6 August 2026" by breaking or circumventing IT security measures. TVP World, by contrast, describes the breach as having "took place on Wednesday," i.e. 12 August, which is the date of public confirmation rather than intrusion. The prosecutor's account is the more authoritative and is consistent with the disclosure chain: Zaufana Trzecia Strona says it was contacted by the alleged perpetrators on Saturday and published first, on Monday. Pollar's timeline places the first ex officio investigative actions on Monday and the Ministry confirmation plus the formal CBZC (Central Bureau for Combating Cybercrime) investigation on 12 August, with Tusk and Gawkowski holding press conferences on 13 August. Note that Pollar dates the Monday investigative step to 11 August, which does not line up with the weekday, so treat the fine-grained dates with caution.

Notably, the attackers went to the press rather than to a leak site. To prove the intrusion, they supplied Zaufana Trzecia Strona's Adam Haertle with his own record from the database plus data on "one of the most important politicians in Poland." MyDr subsequently confirmed it had "become the target of an external, deliberate criminal activity involving some of our data." No threat actor has been publicly identified. Gawkowski said state services are tracking the group and that there is currently no evidence of foreign state involvement.

What Was Taken

The exposed fields reported across sources include full name, PESEL national identification number, date of birth, telephone number, email address, doctors' visit notes, diagnoses, medical conditions, and prescription and medication data. That combination is close to a worst case: a permanent government identifier bound to clinical history and live contact details, in a single 2 TB corpus.

As of the most recent government statements, the data had not surfaced publicly. Gawkowski said the stolen records had not appeared in the public domain or been offered for sale, and that steps were being taken to secure them and prevent onward sale, while explicitly acknowledging there could be no guarantee they will not eventually leak. Haertle likewise confirmed the attackers had not made the database publicly available. Poland's domestic intelligence service (ABW) has proactively contacted prominent public figures whose data was affected in order to reduce blackmail exposure, which is a strong signal that officials regard the political-target records as the most acute near-term risk.

Why It Matters

This is a supply chain concentration failure, not a hospital breach. Roughly half of Poland's population appears in one vendor's database because that vendor is the technological backbone for clinics that patients chose individually. As Brandsit puts it, patients may be in the MyDr database without ever having heard of the brand. Every one of those 12,000 facilities is a separate data controller under GDPR, and each now owns a notification obligation it cannot easily discharge.

Poland's data protection authority, UODO, moved fast on exactly that point. In a public statement on 12 August it reminded controllers who entrusted processing to MyDr of their duty to conduct a risk analysis for the rights and freedoms of data subjects, to report to the President of UODO within 72 hours of establishing a breach where risk exists, and to notify affected individuals directly where the risk is high. Practitioners responding to that post raised the obvious problem: controllers cannot determine what leaked from their own patient population within 72 hours, and the regulator faces a potential flood of thousands of filings. Anyone modelling regulatory exposure from a shared-processor incident should watch how this resolves.

The second-order risk is fraud quality rather than fraud volume. Medical detail makes phishing and voice pretexting dramatically more convincing, and PESEL numbers cannot be rotated like a password. Gawkowski urged the public to use government services to check exposure and to "lock" their PESEL to block credit and identity misuse. Brandsit notes that reported cybersecurity incidents in Poland rose 144 percent year over year in 2025, placing this breach at the top of a steep curve rather than as an outlier.

The Attack Technique

Technical detail is thin, and no source provides a CVE, malware family, or intrusion vector. What is on the record: Tusk described "very sophisticated techniques and methods"; the prosecutor's office frames the offence as unauthorised access obtained by breaking or circumventing IT security measures, carrying up to three years' imprisonment; and Gawkowski stated that the vulnerability exploited by the attackers has since been identified and patched. That last point implies a specific technical flaw in the platform rather than, say, credential stuffing or insider abuse, but no source confirms the class of vulnerability, so treat the exploitation path as unknown.

Two behavioural markers are worth logging. First, the volume: exfiltrating 2 TB implies extended dwell time or a bulk export path such as an exposed API, backup store, or database replica, consistent with access dating to at least 6 August. Second, the extortion tradecraft: contacting a journalist with proof samples, including a high-profile politician's record, is pressure applied through public and political channels rather than through a leak-site countdown. That is a recognised evolution in extortion playbooks and it appears to have been chosen deliberately here. Tusk's assessment of a ransom attempt against the company is a government judgment, and no ransom demand, amount, or actor branding has been published.

What Organizations Should Do

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Ransom likely motive in mass breach of Polish medical data | Poland hit by theft of 19 million patients’ data from medical platf... | Cyberattack in Poland: data breach affecting nearly 19 million citi... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | The MyDr data breach may affect 19 million Poles. The data came fro... | Polish Healthtech Platform MyDr Hit by Major Data Breach Affecting... | W związku z doniesieniami medialnymi dotyczącymi wycieku danych oso...