TechNewsReel
Live

Poland Medical Data Breach Exposes Records of 19 Million Citizens

A leak of over 2TB of sensitive health records from the MyDr system marks one of the largest cyber incidents in Polish history.

TechNewsReel Newsroom · August 13, 2026

Poland is grappling with a catastrophic security failure after a data breach at MyDr, a healthcare software provider, exposed the medical records of approximately 19 million citizens. The incident represents one of the most significant compromises of personal data in the nation's history.

The stolen database exceeds 2TB in size and contains highly sensitive information, including medical histories and PESEL national identification numbers. According to Polish Digital Affairs Minister Krzysztof Gawkowski, the scale of the leak is extraordinary, affecting a vast majority of the population. The MyDr system served as a critical infrastructure point for roughly 12,000 medical facilities across Poland, creating a centralized point of failure that allowed for the massive extraction of data.

The Infrastructure Gap

MyDr operates as a primary provider of confidential medical records software used by a wide network of doctors and clinics. By centralizing the data of thousands of healthcare providers, the system became a high-value target. While the exact cause of the breach remains under investigation, the sheer volume of the leak highlights the vulnerability of Poland's digital healthcare infrastructure. The incident underscores the risks associated with the centralization of sensitive patient data across thousands of disparate medical points.

Implications for National Security

The exposure of PESEL numbers and medical histories creates a severe and immediate risk of identity theft and targeted fraud. Because the leaked data is so specific, criminals can utilize these details to craft highly convincing phishing attacks, deceiving victims by referencing their actual medical backgrounds. In response to the threat, the Polish government has urged citizens to block their PESEL numbers to mitigate the potential for financial and identity-based crimes.

Government Response and Next Steps

Despite the scale of the crisis, the Polish government has adopted a hardline stance against the perpetrators. Minister Gawkowski explicitly stated that the state will not negotiate with cybercriminals or succumb to blackmail, asserting that "nobody will give in to any blackmail."

Attention now turns to the forensic analysis of the MyDr system to determine how the 2TB database was accessed. While the government refuses to pay a ransom, the primary concern remains the permanent exposure of the data, which cannot be recovered once leaked. Authorities continue to monitor for the distribution of the database on the dark web while advising the public on protective measures.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.