Polish healthcare platform MyDr has confirmed (translation here) a cyberattack after hackers claimed to have stolen data belonging to 18.8 million people, roughly half of Poland’s population.
The attackers claim to possess more than 2.5 terabytes of data, while MyDr said the affected information likely dates from 2024 and earlier and that it is still conducting a forensic investigation to determine the scope of the breach.
MyDr processes information including PESEL national identification numbers, prescriptions, medical appointments and other personally identifiable information. As evidence of the breach, the attackers reportedly provided journalists with a prominent Polish politician’s PESEL number, two phone numbers and 25 prescriptions.
“We are dealing with one of the largest data leaks in history,” Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski said.
Denis Calderone, CTO, Suzu Labs:
“This is Poland’s third major cyber incident in as many months, and this one is the worst. Water treatment and energy infrastructure attacks are disruptive, but they’re largely recoverable. In this case we’re talking about a major EMR vendor servicing over 12,000 clinics nationwide. It’s reported that PESEL numbers (national identity numbers), prescriptions, and diagnoses for 18.8 million people were exposed. That’s roughly half the country who just had their personal identification numbers compromised. Ouch!
“MyDr processes roughly three million medical consultations and 2.7 million prescriptions every month. PM Tusk was quick to frame this as a private company, not a state institution. But when a single private vendor is holding that volume of clinical data and national identity numbers, the line between private vendor and public infrastructure is gone. The US learned this lesson with Change Healthcare in 2024. Change was a payments clearinghouse, not an EMR, but the architectural failure was the same: one vendor became the single point of failure for a national healthcare ecosystem. Change hit 192 million Americans. MyDr reportedly hit 18.8 million Poles. Similar proportional impact.
“The Polish government is advising citizens to lock their PESEL numbers through the mObywatel app, and that’s a good first step. But PESEL locking covers specific financial transactions and doesn’t extend to every context where an identity number can be misused. And then there’s the medical data. Prescriptions and diagnoses aren’t just PII, they’re blackmail material. A politician’s 25 prescriptions were already used as proof of the breach. Scale that across 18.8 million people and you have a dataset that will fuel identity fraud, targeted phishing, and extortion for years.
“The full details of how the attackers got in haven’t been disclosed yet. Healthcare organizations and third-party EMR vendors everywhere should be attentive to the revelations from this incident and shore up their own defenses accordingly. The regulatory timing is worth noting. Poland implemented the EU’s NIS2 directive into law on April 3 of this year, 17 months past the EU deadline, and healthcare is a covered sector. But entity registration isn’t due until October, mandatory ISMS implementation until April 2027, and the first cybersecurity audits until 2028. This breach landed in the exact gap between the law existing on paper and anyone having to prove they comply. Countries also need to stop treating national identity numbers as secrets. PESEL, Social Security numbers, and their equivalents were designed as indexes, not authentication factors.”
Damon Small, Board of Directors, Xcape, Inc.:
“Centralizing health records creates immense systemic liability, especially when exfiltration compromises half a nation’s population. While the threat actor identity and precise initial access vector remain unknown, the theft of 2.5 terabytes of medical data from Polish aggregator MyDr exposes 18.8 million people to extortion, targeted medical insurance fraud, and identity theft. Medical records remain among the most valuable assets on the black market, yet exfiltrating terabytes of sensitive files unnoticed highlights a glaring absence of basic network egress monitoring. Security leaders must recognize that protecting health data requires more than perimeter defense. Organizations must deploy strict data loss prevention controls, implement rate-limiting and anomaly detection on database queries, and establish real-time egress monitoring to flag massive data movements before records leave for the public Internet.
“Critical Takeaways
- Monetization risks: Exposed medical records trigger severe risks of identity theft, extortion, and fraudulent medical insurance claims.
- Egress visibility: Siphoning two terabytes of sensitive data undetected underscores a critical failure in network egress monitoring.
- Unknown vectors: Organizations cannot rely solely on preventive edge controls when access paths and threat actor profiles remain unidentified.
“We may not know who stole the data or how they got in, but we certainly know nobody was watching the exit.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Half a population’s medical records exposed in a single incident, and the story almost always becomes about the attacker, when the conversation needs to focus on the years leading up to the attack. 2.5 terabytes does not leave a network quietly. That kind of exfiltration takes time, and time means signals. The decisions that shape an incident like this are made long before anyone finds a way in, and that is where the most valuable reflection has to start.”
Related
This entry was posted on August 14, 2026 at 4:46 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Hackers claim medical data breach affecting nearly 19 million people in Poland
Polish healthcare platform MyDr has confirmed (translation here) a cyberattack after hackers claimed to have stolen data belonging to 18.8 million people, roughly half of Poland’s population.
The attackers claim to possess more than 2.5 terabytes of data, while MyDr said the affected information likely dates from 2024 and earlier and that it is still conducting a forensic investigation to determine the scope of the breach.
MyDr processes information including PESEL national identification numbers, prescriptions, medical appointments and other personally identifiable information. As evidence of the breach, the attackers reportedly provided journalists with a prominent Polish politician’s PESEL number, two phone numbers and 25 prescriptions.
“We are dealing with one of the largest data leaks in history,” Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski said.
Denis Calderone, CTO, Suzu Labs:
“This is Poland’s third major cyber incident in as many months, and this one is the worst. Water treatment and energy infrastructure attacks are disruptive, but they’re largely recoverable. In this case we’re talking about a major EMR vendor servicing over 12,000 clinics nationwide. It’s reported that PESEL numbers (national identity numbers), prescriptions, and diagnoses for 18.8 million people were exposed. That’s roughly half the country who just had their personal identification numbers compromised. Ouch!
“MyDr processes roughly three million medical consultations and 2.7 million prescriptions every month. PM Tusk was quick to frame this as a private company, not a state institution. But when a single private vendor is holding that volume of clinical data and national identity numbers, the line between private vendor and public infrastructure is gone. The US learned this lesson with Change Healthcare in 2024. Change was a payments clearinghouse, not an EMR, but the architectural failure was the same: one vendor became the single point of failure for a national healthcare ecosystem. Change hit 192 million Americans. MyDr reportedly hit 18.8 million Poles. Similar proportional impact.
“The Polish government is advising citizens to lock their PESEL numbers through the mObywatel app, and that’s a good first step. But PESEL locking covers specific financial transactions and doesn’t extend to every context where an identity number can be misused. And then there’s the medical data. Prescriptions and diagnoses aren’t just PII, they’re blackmail material. A politician’s 25 prescriptions were already used as proof of the breach. Scale that across 18.8 million people and you have a dataset that will fuel identity fraud, targeted phishing, and extortion for years.
“The full details of how the attackers got in haven’t been disclosed yet. Healthcare organizations and third-party EMR vendors everywhere should be attentive to the revelations from this incident and shore up their own defenses accordingly. The regulatory timing is worth noting. Poland implemented the EU’s NIS2 directive into law on April 3 of this year, 17 months past the EU deadline, and healthcare is a covered sector. But entity registration isn’t due until October, mandatory ISMS implementation until April 2027, and the first cybersecurity audits until 2028. This breach landed in the exact gap between the law existing on paper and anyone having to prove they comply. Countries also need to stop treating national identity numbers as secrets. PESEL, Social Security numbers, and their equivalents were designed as indexes, not authentication factors.”
Damon Small, Board of Directors, Xcape, Inc.:
“Centralizing health records creates immense systemic liability, especially when exfiltration compromises half a nation’s population. While the threat actor identity and precise initial access vector remain unknown, the theft of 2.5 terabytes of medical data from Polish aggregator MyDr exposes 18.8 million people to extortion, targeted medical insurance fraud, and identity theft. Medical records remain among the most valuable assets on the black market, yet exfiltrating terabytes of sensitive files unnoticed highlights a glaring absence of basic network egress monitoring. Security leaders must recognize that protecting health data requires more than perimeter defense. Organizations must deploy strict data loss prevention controls, implement rate-limiting and anomaly detection on database queries, and establish real-time egress monitoring to flag massive data movements before records leave for the public Internet.
“Critical Takeaways
“We may not know who stole the data or how they got in, but we certainly know nobody was watching the exit.”
Seemant Sehgal, Founder & CEO, BreachLock:
“Half a population’s medical records exposed in a single incident, and the story almost always becomes about the attacker, when the conversation needs to focus on the years leading up to the attack. 2.5 terabytes does not leave a network quietly. That kind of exfiltration takes time, and time means signals. The decisions that shape an incident like this are made long before anyone finds a way in, and that is where the most valuable reflection has to start.”
Share this:
Like this:
Related
This entry was posted on August 14, 2026 at 4:46 pm and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.