Polish prosecutors indict five men over 2024 theft of 13 million medical records
The Regional Prosecutor's Office in Poznan has indicted five individuals for breaching the MyDr platform and querying the EWUS state database to obtain personal data of over 13 million people in 2024.
Five indicted over 2024 healthcare breach
Prosecutors from the Regional Prosecutor's Office in Poznan have submitted an indictment to the District Court in Poznan against five men in connection with an unauthorized intrusion into the MyDr healthcare platform. The cyberattack, carried out in 2024, targeted medical records and state insurance verification services across Poland. Spokesperson Anna Marszalek confirmed the submission of the indictment on 5 October 2026, noting that the five defendants are residents of different regions across the country. All five accused individuals confessed to the allegations during the investigation and provided detailed accounts of their activities to law enforcement authorities.
The individual suspects pleaded guilty to the charges against them and provided extensive explanations in the case.
- Perpetrators breach MyDr healthcare software and extract data from the EWUS database
- Regional Prosecutor's Office in Poznan submits indictment against five defendants to court
Scripted extraction through the EWUS system
According to findings by investigators, the perpetrators obtained unauthorized access to accounts belonging to staff members at medical entities that used the MyDr platform. Once inside the system, the attackers utilized the underlying software structure to implement a custom script. This automated script allowed the group to direct mass queries to the Electronic Verification of Beneficiaries' Insurance (EWUS) service operated for the National Health Fund (NFZ).
The attackers sent over 18 million automated queries to the EWUS service, extracting personal data belonging to more than 13 million Polish citizens. The extracted records included first names, last names, national identification numbers (PESEL), and information regarding whether each individual held active health insurance coverage. Following an investigation conducted by the regional prosecution and officers from the Poznan board of the Central Bureau for Combating Cybercrime (CBZC), authorities successfully recovered the entire database of illegally obtained NFZ records. The MyDr platform was later subject to an even larger cyberattack in 2026.
- Automated queries sent
- 18 million
- Individuals affected
- 13 million
Specific charges and money laundering counts
The indictment outlines distinct criminal charges for each participant in the 2024 breach. Tomasz B. is charged with breaching IT security safeguards at a medical center, submitting unlawful queries to the EWUS system, and obtaining unauthorized access to confidential records. In addition to unauthorized access, prosecutors charged Tomasz B. with the unlawful processing of personal data belonging to NFZ beneficiaries and money laundering.
A second defendant, Jakub K., faces charges for creating computer software designed to break IT security protections and distribute unauthorized access tools to other individuals. Investigators also charged Jakub K. with obtaining direct access to sensitive data stored within online patient accounts.
System intrusions and potential prison sentences
The remaining three defendants, identified in court documents as Wojciech G., Patryk K., and Marcin W., face charges related to unauthorized access to information achieved by overcoming system security measures. Each of these three suspects participated in breaching the safeguards established on the affected medical IT networks.
The offenses outlined in the indictment carry potential prison sentences of up to 8 years for certain violations and up to 12 years for the most severe charges, including money laundering and large-scale data processing. The five men now await judicial proceedings before the District Court in Poznan following the formal filing of the case.
