
Poland confirms massive medical data breach affecting nearly 19 million citizens
A cyberattack on MyDr, a major Polish medical documentation provider, exposed records of nearly 19 million people, Deputy PM Gawkowski confirmed after an emergency cybersecurity meeting on 12 August.
Cyberattack confirmed
Deputy Prime Minister and Minister of Digitalization Krzysztof Gawkowski confirmed on 12 August that a cyberattack on MyDr, one of Poland's largest providers of Electronic Medical Documentation systems, resulted in an extraordinary data leak affecting nearly 19 million people. Gawkowski spoke after a meeting of the Joint Cybersecurity Operations Center convened at noon on Wednesday. He described the incident as one of the largest in Poland's history. The company itself confirmed that 19 million records were stolen, according to the minister.
The perpetrators contacted the website Zaufana Trzecia Strona on Saturday, claiming to possess data of over 18 million Poles from medical systems. They sent sample data that turned out to be partly genuine. Gawkowski first disclosed the incident on Monday on platform X.
What data was compromised
MyDr provides medical facilities with systems for storing patient documentation, issuing prescriptions, managing visits, and handling e-sick leaves. The platform handles approximately 3 million visits and 2.7 million prescriptions monthly. Gawkowski warned that the stolen data could link names, surnames, and addresses with information about prescriptions, medications, and health conditions.
These could be data that will serve as a basis for blackmail.
He added that these are valuable data that criminals or various institutions might want to purchase for analysis, blackmail, or other activities affecting ordinary life. Medical facilities continue to operate normally, as the incident did not take the system offline. Gawkowski assured that vulnerabilities have been patched and the system remains secure.
- Person contacts Zaufana Trzecia Strona claiming to hold data of over 18 million Poles from medical systems
- Gawkowski discloses cybersecurity incident at MyDr on platform X
- Joint Cybersecurity Operations Center convenes
- Gawkowski confirms data leak of nearly 19 million people at press conference
Government response
Gawkowski is in constant contact with special services coordinator Tomasz Siemoniak, Health Minister Jolanta Sobierańska-Grenda, and Personal Data Protection Office head Mirosław Wróblewski. The Central Bureau for Combating Cybercrime is handling the operational side of the investigation, in contact with the prosecutor's office. Authorities are investigating whether the breach resulted from human error, a system vulnerability, sabotage, or negligence on the company's part. Gawkowski stated that nothing indicates an attack by another state. He warned that MyDr could face penalties if investigators find the company lacked required security measures or investments in cybersecurity.
Citizens advised to act
Information gathered by services will be published on the Bezpieczne Dane website (bezpiecznedane.gov.pl), where citizens can check whether their data appears in the stolen datasets. Shortly after Gawkowski's conference, the site experienced login problems. The minister urged citizens to lock their PESEL number, which takes five seconds in the mObywatel app or can be done at any municipal office.
- Monthly visits
- 3 millions
- Monthly prescriptions
- 2.7 millions
- PESEL numbers claimed by perpetrators
- 18.8 millions
- Records confirmed stolen
- 19 millions
He declared that the state will not negotiate with criminals or pay any ransom.
No one in Poland will pay any ransom because someone thinks they can profit from cybercrime.
MyDr's position
MyDr stated it is conducting an internal investigation into a potential incident affecting part of its systems. The company said it immediately launched incident response procedures upon receiving information about the matter. Internal teams from Security, Engineering, and Infrastructure are working with external cybersecurity experts and legal advisors. Małgorzata Pragłowska, who supports ZnanyLekarz in communications, provided the statement to TVN24. The company said it has notified relevant authorities and is cooperating closely with them.

