Poland Breach: 19 Million Citizens' Medical Records Exposed
A cyberattack on software provider MyDr leaked 2 terabytes of sensitive health data, affecting a vast majority of the Polish population.
Poland is grappling with an unprecedented cybersecurity crisis after a massive data breach exposed the medical records of nearly 19 million citizens. The leak represents one of the largest thefts of personal information in the nation's history, compromising sensitive health data on a national scale.
Polish Digital Affairs Minister Krzysztof Gawkowski confirmed that approximately 2 terabytes of personal data were stolen during the attack. The breach originated within the systems of MyDr, a software provider utilized by a wide network of doctors and healthcare facilities across Poland. According to Minister Gawkowski, the company confirmed that 19 million records were taken, noting that the stolen files contain various types of data that can be linked to create detailed profiles of individuals.
The Scope of the Vulnerability
The attack targeted a critical node in Poland's healthcare infrastructure. By compromising MyDr, the attackers gained access to a centralized point of failure that served numerous clinics and private practices. This systemic vulnerability allowed the perpetrators to extract a massive volume of confidential records without needing to breach individual medical offices one by one. The scale of the theft suggests a sophisticated operation capable of exfiltrating terabytes of data from a professional software environment.
National Security Implications
The consequences of this breach extend beyond privacy concerns. Because the leaked data involves sensitive medical histories, the Polish population faces an elevated risk of identity theft and medical fraud. Furthermore, the nature of health records makes this dataset a prime tool for targeted blackmail, as private diagnoses or treatment histories can be weaponized against individuals. The sheer volume of the leak—affecting nearly the entire adult population—transforms a corporate security failure into a matter of national security.
Government Response and Next Steps
Polish cybersecurity services are investigating the incident to determine the exact method of entry and to secure remaining vulnerable information. The government has taken a hardline stance regarding potential ransom demands. Minister Gawkowski stated explicitly that "nobody will negotiate with anyone" and that the state will not give in to blackmail.
While the volume of stolen data is confirmed, the full extent of how the information is being distributed or sold on the dark web remains under investigation. Authorities are now focused on mitigating the fallout for the millions of affected citizens while auditing other third-party software providers within the healthcare sector to prevent similar systemic collapses.