SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
▣ Breach POLAND-NATIONAL-HE 2026-08-13

MyDr: Nearly 19 Million Polish Patient Records Stolen in Suspected Extortion Breach

"Poland's Ministry of Digitalization confirmed on 12 August 2026 that MyDr sp. z o.o., a private vendor of electronic medical records software used across the Polish healthcare system, was breached and that data…"

Poland's Ministry of Digitalization confirmed on 12 August 2026 that MyDr sp. z o.o., a private vendor of electronic medical records software used across the Polish healthcare system, was breached and that data belonging to close to 19 million people was taken. Digital affairs minister Krzysztof Gawkowski called it "one of the largest incidents in Poland's history." Prime Minister Donald Tusk said a day later that the techniques were sophisticated and the motive appears to be criminal ransom extortion. The headline figure is contested: the attackers claim 18,814,422 unique PESEL numbers, the government says nearly 19 million and has stated the company confirms it, and MyDr's own incident page says it cannot confirm any quantity or type of data at all. Nearly 19 million is roughly half of Poland's population.

What Happened

MyDr builds records and practice-management software for Polish clinics. Pollar reports the company serves 12,000 healthcare facilities; Notes From Poland describes it more loosely as "thousands of medical facilities." StartupKit notes the Docplanner (ZnanyLekarz) group announced its acquisition of MyDr on 9 January 2023, which places the vendor inside one of the larger healthcare technology groups in the region.

The timeline that emerges from the sources runs roughly as follows. Prosecutor Piotr Antoni Skiba, spokesperson for the Warsaw district prosecutor's office, stated that the perpetrator gained unauthorized access to MyDr's servers no later than 6 August 2026, by breaking or circumventing IT security measures. On Saturday 8 August, the Polish security news service Zaufana Trzecia Strona was contacted by the alleged perpetrators, who claimed to hold the data of around 18.8 million people and who supplied a sample. Zaufana Trzecia Strona broke the story on Monday 11 August, the same day the first investigative actions were taken ex officio. On 12 August the Ministry of Digitalization confirmed the attack, Poland's CBZC cybercrime bureau formally opened an investigation, and MyDr acknowledged it had "become the target of an external, deliberate criminal activity involving some of our data." On 13 August, Tusk and Gawkowski held press conferences.

Accounts genuinely differ on the central fact, and this is worth stating plainly rather than smoothing over. StartupKit, which compiled the discrepancy, points out that the government statement and MyDr's own page are both primary-adjacent sources published hours apart and that they contradict each other: Gawkowski said on 12 August that nearly 19 million records were stolen "which the company itself confirms," while MyDr's page, updated at 18:35 CET the same day, says the company cannot confirm the quantity or type of data disclosed and describes the affected data as "most likely historical, from 2024 and earlier years." Zaufana Trzecia Strona verified part of the attackers' sample but said it could verify neither the 18.8 million figure nor the claimed archive size. No independently confirmed record count exists as of publication.

One detail reported by Notes From Poland, citing Zaufana Trzecia Strona, is worth flagging for its political weight: the attackers also sent a screenshot from the compromised database showing the personal data of "one of the most important politicians in Poland." The attackers have not been identified.

What Was Taken

Per Pollar, the stolen database exceeds 2 TB and includes names, PESEL national identification numbers, phone numbers, email addresses, doctors' visit notes, and prescription information. The attackers themselves claimed roughly 2.5 TB alongside the 18,814,422 PESEL figure, per StartupKit. Notes From Poland describes the compromised set as patients' personal information plus medical details including diagnoses and prescriptions.

Two things make this materially worse than a typical credential dump. First, the PESEL number is Poland's universal identifier and encodes date of birth and sex; paired with name, phone, and email it is a ready-made identity fraud kit, which is precisely why Gawkowski urged citizens to use government services to check exposure and to "lock" their PESEL against fraudulent use. Second, visit notes, diagnoses, and prescription histories are not resettable. A leaked password rotates in a minute; a leaked psychiatric diagnosis or HIV prescription record is permanent leverage for extortion, coercion, and targeted social engineering, and at this scale it constitutes a standing intelligence resource on a sizeable portion of a NATO member state's population, including its officials.

As of writing, MyDr said it had no evidence the data had been published. The unresolved question is whether the actors are holding it for a ransom negotiation, which is what Tusk's extortion framing implies, or preparing a staged public leak.

Why It Matters

This is a third-party software vendor compromise, not a hospital compromise. One supplier sitting behind 12,000 facilities collapsed the security posture of the entire Polish outpatient sector into a single point of failure. No individual clinic's controls were in a position to prevent this, and no clinic can currently tell its own patients what was taken, because the vendor itself says it does not know.

The wider Polish context in the reporting set is not incidental. TechCrunch reported on 7 August that security researchers who scanned Polish internet-facing infrastructure found courts, hospitals, and airports exposed to attack, published days before this breach surfaced. Separately, CERT Polska's post-mortem on the December 2025 energy sector campaign, presented at DEF CON 34 and covered by Infosecurity Magazine, Security Affairs, and Help Net Security, documents a Russian-linked intrusion set operating against Polish critical infrastructure. Poland is under sustained multi-vector pressure. That said, nothing in the available sources links the MyDr breach to that state-backed activity, and Tusk's own assessment points the other way, to ordinary criminal extortion. Do not merge the two threads.

There is also a disclosure failure worth naming. StartupKit's argument is that MyDr, like Change Healthcare, Salesloft Drift, Free Mobile, and Tea, had no supported channel for an outsider to report a flaw. A vulnerability disclosure program would not have prevented the intrusion. It changes who finds out first and how long it takes. In this case, the attackers chose the disclosure channel themselves by mailing a journalist.

The Attack Technique

Honestly: the initial access vector for MyDr is not public. What is on the record is the prosecutor's characterisation that the perpetrator obtained unauthorized access to MyDr's servers no later than 6 August 2026 by breaking or circumventing IT security safeguards, an offense carrying up to three years' imprisonment under the cited statute, and Tusk's description of "very sophisticated techniques and methods." Treat "sophisticated" as a political characterisation from a press conference, not a technical finding. Bulk exfiltration of multi-terabyte databases far more often follows exposed credentials, an unpatched edge appliance, or an over-permissioned integration account than anything exotic.

For contrast, and as a separately sourced example of a fully documented Polish intrusion chain, CERT Polska's report on the 29 December 2025 attack against a combined heat and power plant serving around 50,000 residents lays out every hop. Attackers compromised a FortiGate VPN and firewall at a wind farm, pivoted through a Teltonika cellular router on the same network, and used an SSH tunnel to reach a private Access Point Name network operated by a distribution system operator. CERT Polska says this is the first documented case of threat actors reaching an OT network through a private APN, infrastructure that operators had assumed was isolated. Repeated scanning of the APN surfaced a WAGO PFC200 PLC at the CHP plant whose web interface was reachable and protected only by default admin credentials. From there the actors reached the plant's OT network over SSH and located three Siemens PLCs, which were switched to STOP mode and password-protected, shutting down a steam turbine and the water treatment system and interrupting cogeneration. Operators restored the installation before heat or power to customers was disrupted. That incident occurred the same day as coordinated attacks affecting 30 renewable energy facilities and another CHP plant, part of a campaign attributed to the Russian state-backed group Sandworm. Marcin Dudek of CERT Polska, described by Infosecurity Magazine as head of the organisation, disclosed the findings at DEF CON 34; analysis took over three months, which is why it was absent from the January 2026 report. Staff initially assumed contractor error, because maintenance was underway that day, and reported it only for information.

The transferable lesson across both incidents is the same: the compromise arrived through infrastructure nobody was watching, and in both cases the defenders' first read of the event was wrong.

What Organizations Should Do

Sources: Medical records of nearly 19M Poles leaked in major cyber breach | Security researchers scanned the Polish web and found courts, hospi... | Russian-Linked Hackers Accessed Polish Power Plant OT Through APN -... | Hackers Cross From IT to OT Through a Private APN in Poland | Previously unseen entry vector used to breach Polish energy plant -... | Poland hit by theft of 19 million patients’ data from medical platf... | Cyberattack on MyDr exposes medical data of nearly 19 million Poles... | MyDr Breach: Five Leaks, One Missing Disclosure Channel StartupKit