A data breach has affected half of Poland’s population after a cybercrime gang gained access to MyDr, a medical documentation software provider, on August 6, 2026.
The breach affected MyDr EDM, an integrated software system that includes electronic health records, electronic prescriptions, telemedicine, appointment scheduling, and e-sick leave functionalities. The system also fully integrates with the Polish government’s P1 platform, which collects and analyzes the nation’s health data. The widely adopted system handles approximately 3 million visits and 2.7 million prescriptions per month.
Half of the Polish Population impacted by MyDr data breach
The data breach leaked sensitive information, including PESEL numbers, similar to Social Security Numbers, putting victims at risk of identity theft. It also leaked names, telephone numbers, email addresses, health conditions, doctor’s notes, and prescriptions.
However, MyDr could not conclusively determine what information was stolen. Nevertheless, Polish authorities estimate that the data breach affected over 12,000 healthcare providers, 47,000 doctors’ offices, and 18.8 million individuals, half of Poland’s population. Nevertheless, the medical records provider claims the data breach affected historical data dating back to 2024.
“Our investigation indicates that the data involved in the incident is likely historical, dating back to 2024 and earlier,” it stated.
As soon as MyDr learned of the data breach, it launched an investigation involving external cybersecurity experts and notified the President of the Personal Data Protection Office (UODO) and other relevant authorities. Polish authorities are also pursuing legal action against unauthorized individuals who accessed MyDr’s health information infrastructure.
Meanwhile, MyDr has terminated the threat actor’s access, implemented additional security measures to protect personal information, and has started cooperating with the country’s cyber authority, CERT Polska, and the Central Bureau for Combating Cybercrime (CBZC). An investigation is currently underway to determine the scope of the incident. However, Polish authorities say the attacker gained access to all parts of MyDr’s systems, suggesting that the data breach was extensive.
Nevertheless, MyDr says the cyber attack did not disrupt operations for patients or doctors. Additionally, the company has no evidence that the stolen data has been published on the dark web and is actively monitoring the underground cybercrime markets. So far, no hacking group has taken responsibility for the data breach. The attack vector exploited also remains undisclosed.
However, the alleged hackers told cybersecurity company Zaufana Trzecia Strona that they exploited a “remote code execution through an XXE vulnerability in PKCS#12 certificate handling” functionality to obtain MyDr’s GitHub API key and source code and compromise the company’s AWS infrastructure. The attackers claim they stole 2.5 terabytes of data, a claim that could not be independently verified.
“The Polish government is advising citizens to lock their PESEL numbers through the mObywatel app, and that’s a good first step,” said Denis Calderone, CTO, Suzu Labs. “But PESEL locking covers specific financial transactions and doesn’t extend to every context where an identity number can be misused.”
“And then there’s the medical data. Prescriptions and diagnoses aren’t just PII, they’re blackmail material. A politician’s 25 prescriptions were already used as proof of the breach. Scale that across 18.8 million people and you have a dataset that will fuel identity fraud, targeted phishing, and extortion for years,” added Calderone.
Health information systems are a prime target
Health technology systems are a prime target because health data fetches a premium price on the dark web, and disruptions to these systems are often life-threatening, making companies more willing to pay a ransom.
“This is Poland’s third major cyber incident in as many months, and this one is the worst. Water treatment and energy infrastructure attacks are disruptive, but they’re largely recoverable,” added Calderone.
Hackers have previously targeted health information systems. In 2023, hackers breached HCA Healthcare, affecting over 11 million individuals, Perry Johnson & Associates, a medical transcription company, impacting over 8 million people, WellTok, a healthcare technology firm, dental insurer MCNA Dental, and pharmacy and healthcare provider Pharmamerica, affecting nearly 6 million people.
In 2024, suspected nation-state actors also breached UnitedHealth Group’s subsidiary Change Healthcare, a claims-processing firm, affecting over 100 million Americans.
