INFORMATICS

The Best

Cyber Attack on MyDr – One of the Largest Data Breaches in Polish History. Detailed Incident Analysis

Star InactiveStar InactiveStar InactiveStar InactiveStar Inactive
 

Cyber Attack on MyDr – One of the Largest Data Breaches in Polish History. Detailed Incident Analysis

In August 2026, Poland experienced one of the most serious cybersecurity incidents in the country’s history. The victim was MyDr, a provider of Electronic Medical Records (EDM) software used by thousands of healthcare facilities. According to official confirmations from the Ministry of Digital Affairs and findings of the Joint Cybersecurity Operations Center, unauthorized access affected data relating to nearly 19 million people (approximately 18,814,422 unique PESEL numbers according to the attackers’ claims) and more than 12,000 medical facilities.

Scale and Nature of the Breach

MyDr processes around 3 million visits and 2.7 million e-prescriptions monthly. The historical data (up to April 2024) stored in the company’s systems included, among other things:

  • PESEL numbers,
  • visit histories,
  • prescription and medication information,
  • contact details,
  • potentially information about medical conditions.

The stolen database is estimated at over 2 TB (up to 2.5 TB according to the attackers). The data is historical — current operations of healthcare facilities, prescription issuance, and patient care were not disrupted. Systems were isolated, and the company is cooperating with authorities.

How the Incident Unfolded

  1. Detection and first signals – Around 10 August 2026, MyDr announced it was investigating a security incident. At the same time, individuals claiming to be the perpetrators contacted the cybersecurity site Zaufana Trzecia Strona, providing evidence (screenshots containing data of politicians and journalists).
  2. Official confirmation – On 12 August 2026, following a meeting of the Joint Cybersecurity Operations Center, Digital Affairs Minister Krzysztof Gawkowski officially confirmed the scale of the breach as “extraordinary.” The case is being handled by the Central Bureau for Combating Cybercrime, the National Prosecutor’s Office, the Personal Data Protection Office (UODO), special services, and the Ministry of Health.
  3. Response – Data is being progressively transferred to the bezpiecznedane.gov.pl portal, where citizens can check whether their information was affected. Immediate freezing of the PESEL number (e.g., via the mObywatel app) is strongly recommended.

How Did the Hackers Gain Access? (Attackers’ Version – Officially Unconfirmed)

According to the account given by the alleged perpetrators to Zaufana Trzecia Strona (not yet confirmed by authorities or MyDr), the initial attack vector was an XXE (XML External Entity) vulnerability related to the handling of PKCS#12 certificates. This allegedly allowed remote code execution (RCE). The attackers then obtained a GitHub API key leading to the system’s source code and subsequently gained access to the infrastructure running on AWS. They also demonstrated control over company tools (Jira, HubSpot CRM) and the ability to send SMS messages from the official company account.

Important note: The above scenario comes solely from the alleged attackers and has not been publicly confirmed by law enforcement or the company. A detailed investigation is ongoing. The motive appears to be financial (medical data is highly valuable on the black market for targeted phishing and identity theft) rather than sabotage.

Consequences and Recommendations

The incident highlights the risks associated with concentrating sensitive medical data with external software providers. Individual medical facilities remain the data controllers, while MyDr acted as a processor. Citizens should:

  • check their status on bezpiecznedane.gov.pl,
  • freeze their PESEL number,
  • exercise heightened caution with emails/SMS related to medical services (phishing risk).

The investigation continues. We will update this article as official findings become available.


Źródła: komunikaty Ministerstwa Cyfryzacji, MyDr, raporty Zaufanej Trzeciej Strony, Business Insider, Spidersweb i inne wiarygodne media (stan na 13 sierpnia 2026).

 

Search