Poland Confirms Medical Data Breach Affecting 19 Million Citizens
A cyberattack on healthcare software provider MyDr exposed sensitive medical histories and national ID numbers for a vast majority of the Polish population.
A massive cyberattack on a Polish healthcare software provider has compromised the personal and medical data of nearly 19 million citizens. The breach represents one of the largest exposures of sensitive health information in the country's history.
Polish Digital Affairs Minister Krzysztof Gawkowski confirmed the breach on August 12, revealing that approximately 2 terabytes of data were stolen from the systems of MyDr. The provider serves a wide network of healthcare facilities and doctors across Poland. According to government officials, the stolen database contains highly sensitive information, including detailed medical histories and PESEL numbers, which serve as the primary national identification system for Polish citizens.
The Infrastructure Vulnerability
The breach originated within MyDr, a third-party software vendor integrated into the operational workflows of various medical clinics and healthcare providers. By targeting a single software provider rather than individual hospitals, attackers gained access to a centralized repository of patient data. This incident underscores a growing trend in cybersecurity where the software supply chain becomes the primary vector for large-scale data theft, bypassing the perimeter defenses of individual medical facilities.
Implications for National Security
The scale of the leak is immense, potentially exposing a significant portion of the entire Polish population to severe risks. The combination of medical records and PESEL numbers provides a comprehensive toolkit for criminals to engage in identity theft and medical fraud. Furthermore, the specificity of the leaked health data allows for highly targeted phishing attacks, where bad actors can use actual medical conditions to manipulate victims into revealing further financial or personal information.
Government Response and Next Steps
In response to the crisis, the Polish government has convened an urgent meeting of its national cybersecurity team to assess the full extent of the leak and implement mitigation strategies. While the volume of stolen data is confirmed, authorities are still working to determine the exact methods used to penetrate MyDr's systems. The government's immediate focus remains on notifying affected citizens and securing remaining healthcare infrastructure to prevent secondary attacks. Observers are now watching for updates on whether the data has been published on the dark web or if it remains in the hands of the attackers.