MyDr medical records platform breach exposes data on nearly 19 million Poles
Poland's Ministry of Digital Affairs confirmed that attackers stole more than 2 TB of patient data from MyDr, a medical documentation platform used by about 12,000 facilities, affecting nearly half the country's population.
- Victim
- MyDr
- users
- 18.8M
On 12 August 2026, Poland's Ministry of Digital Affairs confirmed that attackers had stolen more than 2 terabytes of patient data from MyDr, a Warsaw-based provider of electronic medical documentation software used by around 12,000 healthcare facilities. Minister Krzysztof Gawkowski described it as an extraordinary leak affecting nearly 19 million people, roughly half of Poland's population.
The attackers had approached Polish security outlets over the weekend of 8 August with samples. According to the claim published by BadCyber, the haul contained 18,814,422 unique PESEL numbers (Poland's lifetime national identification number) and about 2.5 TB of data in total. To prove their access, the attackers leaked the PESEL number, phone numbers and prescriptions of a senior Polish politician.
What was exposed
The stolen records reportedly include patient names, dates of birth, PESEL numbers, phone numbers and email addresses, along with consultation notes, diagnoses, visit history and prescription records. The attackers also claimed to hold internal company correspondence and databases of doctors and employees. MyDr EDM integrates with the government's P1 national e-health platform for e-prescriptions and e-sick leave, which is why its records mirror so much of the country's patient activity.
The attackers claimed they gained remote code execution through an XXE flaw in the handling of PKCS#12 certificates, then found a GitHub API key that led them into the company's AWS infrastructure. MyDr said it had activated its incident response procedures, brought in external experts and notified the authorities. The Central Bureau for Combating Cybercrime opened an investigation, and the government urged citizens to check their exposure and consider blocking their PESEL to prevent fraudulent loans.
Why it matters
A single breach at one software vendor exposed sensitive health data on a scale usually associated with national registries. Because PESEL numbers never change, the data has long-term value for identity fraud and targeted scams. Weeks later, a second Polish medical software provider, Qbusoft, was also breached, raising questions about the security of the vendors that connect to the national e-health system.
Timeline
The attackers contact Polish security outlets over the weekend with samples of the stolen data.
Poland's Ministry of Digital Affairs confirms that more than 2 TB of patient data was taken from MyDr, affecting nearly 19 million people.
BadCyber publishes the attackers' claim of 18,814,422 unique PESEL numbers and about 2.5 TB of data, along with MyDr's statement that it is investigating.
Poland's data protection authority reports more than 2,000 breach notifications from data controllers linked to the incident.
Sources
- badcyber.comhttps://badcyber.com/hackers-claim-to-have-stolen-the-data-of-more-than-18-million-poles-from-mydr/
- unn.uahttps://unn.ua/en/news/a-massive-data-breach-in-poland-affected-nearly-19-million-people
- gblock.apphttps://www.gblock.app/articles/poland-mydr-healthcare-breach-19-million-2026
- helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/09/29/qbusoft-medyc-data-breach-poland/
- bankinfosecurity.comhttps://www.bankinfosecurity.com/poland-probes-hack-second-health-software-vendor-a-32980