MyDr Cyberattack

Poland’s Largest Data Breach: MyDr Hack Exposes Health Data of 19 Million People

MyDr data breach, MyDr, Poland data breach, MyDr data breach exposes 19 million Polish citizens, Poland healthcare data breach 2026, MyDr cyberattack health data leak
Facebook
X
LinkedIn
Reddit
WhatsApp

A cyberattack on Polish healthcare provider MyDr has exposed sensitive health data belonging to up to 19 million people.

MyDr operates one of Poland’s largest electronic health record systems and works with thousands of medical practices and clinics across the country. Poland’s specialist cybersecurity portal Zaufana Trzecia Strona received the first indication of the attack on August 10, directly from the alleged attackers. They claimed to have obtained records linked to 18,814,422 unique PESEL numbers, Poland’s equivalent of a Social Security number, as well as more than 2.5 terabytes of data.

Ad

To substantiate their claims, the attackers asked the portal to verify the PESEL numbers of four industry volunteers. MyDr itself publicly confirmed the same day that it was investigating a serious security incident affecting its network.

“There has been an extraordinary data breach affecting almost 19 million people.”

Krzysztof Gawkowski, Poland’s Deputy Prime Minister and Minister of Digital Affairs

Ad

The stolen database reportedly exceeds 2 terabytes and includes information on issued prescriptions, medical appointments, prescribed medications and documents presented to doctors. Gawkowski described the incident as one of the most significant cybersecurity incidents in Poland’s history.

MyDr Data on Politician Provided as Evidence

According to Cybernews, the attackers provided Polish media with a PESEL number, two phone numbers and a list of 25 prescribed medications belonging to a prominent Polish politician as evidence that the stolen data was genuine. Gawkowski confirmed the information when asked, but did not disclose further details.

The minister said there are currently no indications that the attack was politically motivated. Instead, he believes it is almost certainly the work of financially motivated cybercriminals. He explicitly ruled out both paying the extortionists and having the government buy back the stolen data, but did not disclose the amount demanded.

Government Sets Up Data Breach Verification Portal

The Polish government has announced plans to give affected citizens a way to check whether their personal information was included in the breach via bezpiecznedane.gov.pl once the stolen data packages have been fully reviewed and consolidated. Until then, Gawkowski is advising all citizens to proactively block their PESEL number through the mObywatel app or directly through their local municipal authority. According to the minister, the process takes only around five seconds.

In a separate statement, MyDr said that the affected data largely dates from 2024 or earlier and does not necessarily concern all of the company’s customers and patients. A final assessment of the scope and nature of the exposed information is still pending.

Security experts warn that a breach of this nature presents particular risks. Unlike passwords or payment cards, exposed health data and PESEL numbers cannot simply be replaced. In addition to conventional identity theft, experts are particularly concerned about prescription drug fraud and targeted extortion based on individuals’ medical records. For high-profile victims such as politicians, the data could also potentially be exploited for political purposes.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel