Europe

Poland Data Breach Exposes Medical Records of Nearly 19 Million People

Poland, Masovian Voivodeship — Massive cyberattack compromises sensitive medical and personal data, prompting government warnings and urgent identity protection measures

Poland is confronting one of the country’s largest suspected data breaches after hackers allegedly gained access to information belonging to almost 19 million people through MyDr, a company providing digital services to numerous medical facilities across the country.

The compromised information reportedly includes highly sensitive personal records alongside medical information, including diagnoses and prescriptions. The scale of the alleged intrusion has raised serious concerns about privacy, identity theft and potential criminal exploitation of healthcare information affecting millions of Polish residents.

Digital Affairs Minister Krzysztof Gawkowski described the incident on Wednesday as one of the largest cybersecurity incidents in Poland’s history. His warning reflected the unusually broad scope of the suspected breach and the sensitivity of the information involved.

Gawkowski urged people to use government services to determine whether their personal information had been affected. He also encouraged citizens to lock their national identity numbers, a precaution designed to make fraudulent financial or administrative activity more difficult.

The attack reportedly targeted MyDr, whose services are used by thousands of medical facilities in Poland. Because healthcare systems routinely handle extensive personal records, any unauthorized access can potentially expose information far beyond names and contact details.

According to Polish cybersecurity news service Zaufana Trzecia Strona, the alleged perpetrators contacted the publication on Saturday before publicly drawing wider attention to the incident. They claimed to have obtained data concerning approximately 18.8 million individuals.

The hackers also reportedly provided a screenshot from the allegedly compromised database. Zaufana Trzecia Strona said the image contained information belonging to what the attackers described as one of Poland’s most important politicians.

The identity of the hackers has not been established publicly. Authorities have not confirmed who was responsible for the intrusion, leaving investigators to determine whether the attack was conducted by an organized criminal group, independent hackers or another threat actor.

MyDr subsequently confirmed that it had become the target of what it described as external, deliberate criminal activity involving some of its data. The company’s statement acknowledged the attack while emphasizing that the investigation remained ongoing.

In an update issued Wednesday, MyDr said there was no evidence at that time that the compromised information had been published elsewhere. The statement provides some reassurance, although cybersecurity specialists generally warn that stolen information can remain privately held before later being exploited or released.

The potential exposure of medical information makes the incident particularly serious. Diagnoses and prescriptions can reveal intimate details about an individual’s health and treatment, making healthcare databases among the most sensitive categories of personal information held electronically.

Unlike ordinary contact information, medical records can have long-lasting consequences if improperly disclosed. Unauthorized access could potentially facilitate extortion, impersonation, targeted scams or discrimination, depending on the nature of the information obtained and how criminals attempt to exploit it.

The reported scale also makes the incident significant from a national cybersecurity perspective. A breach involving nearly 19 million people represents a substantial proportion of Poland’s population, potentially affecting citizens across regions and creating an unusually large pool of information for criminals.

The government’s recommendation to lock national identification numbers is therefore particularly important. Poland’s national identification system is commonly used for official and financial purposes, meaning protective measures can help reduce opportunities for criminals attempting to misuse stolen identity information.

Citizens who suspect that their information may have been exposed are being encouraged to use official government services to check their status. Authorities have emphasized preventative action while investigators work to establish precisely what information was accessed during the intrusion.

The incident also highlights the growing cybersecurity risks faced by healthcare organizations. Medical providers increasingly depend on interconnected digital systems for appointments, prescriptions, patient records and communication, creating valuable targets for criminals seeking large quantities of sensitive information.

Companies providing technology services to healthcare institutions can represent particularly attractive targets because a single successful intrusion may provide access to information originating from numerous facilities. This concentration can magnify the consequences of an otherwise isolated security failure.

Cybersecurity incidents involving healthcare data have increased international concern in recent years as attackers recognize the value of medical records. Unlike passwords, medical histories cannot simply be changed after exposure, making effective protection and rapid response especially important.

The Polish incident may also prompt questions about the security arrangements surrounding third-party technology providers. Healthcare facilities can maintain strong internal protections while still facing significant risks when external companies process, store or transmit sensitive information on their behalf.

Investigators will need to determine how the attackers entered MyDr’s systems, what security controls were bypassed and how much information was actually accessed. Establishing whether the attackers copied entire databases or only selected records will be crucial to assessing the eventual impact.

Another major question concerns whether the alleged stolen information will appear online. MyDr has said there is currently no evidence that the data has been published, but authorities must continue monitoring criminal forums and other channels for signs of distribution.

The screenshot reportedly supplied by the attackers could become an important investigative lead. If the information shown can be authenticated, investigators may be able to establish that the attackers gained genuine access to the company’s systems rather than making an unsupported claim.

For affected individuals, the uncertainty itself presents a challenge. People may not know whether their information was accessed, while criminals could potentially attempt scams using personal details even before a complete investigation determines the breach’s precise boundaries.

Officials are consequently emphasizing preventative measures rather than waiting for evidence of financial losses or identity fraud. Locking national identification numbers can reduce certain risks, while citizens should remain cautious about unexpected calls, messages, emails or requests for personal information.

The case also demonstrates why large healthcare databases require robust security protections, continuous monitoring and rapid incident-response procedures. A successful attack against one service provider can potentially affect patients connected to many different medical institutions simultaneously.

Polish authorities are expected to continue working with MyDr and cybersecurity specialists to establish the full circumstances surrounding the incident. The investigation will need to clarify the number of affected people, the categories of exposed information and the attackers’ ultimate intentions.

For now, the reported breach remains an evolving cybersecurity crisis, with millions potentially affected and important questions still unanswered. Government warnings, precautionary identity protections and continued monitoring will be central to limiting the damage while investigators determine the incident’s full extent.

 

This article was created using automation technology and was thoroughly edited and fact-checked by one of our editorial staff members

CCE NEWS

Recent Posts

Engine Failure Sends Debris Through Ryanair Cabin Window During Flight

A passenger aboard a Ryanair-operated flight suffered serious injuries after engine debris shattered a cabin… Read More

1 day ago

Romania Shuts Nuclear Plant as Danube Water Levels Reach Crisis Point

Romania shut down Cernavodă nuclear plant after exceptionally low Danube River levels disrupted cooling operations,… Read More

1 day ago

PSG Agree Deal in Principle to Sign Barcelona Forward Ferran Torres

Paris Saint-Germain are closing in on Ferran Torres after agreeing a deal in principle with… Read More

1 day ago

Train Derailment Near Lewes Leaves 20 Injured as Major Incident Declared

Twenty passengers were injured after a Southern train derailed near Lewes in East Sussex, with… Read More

1 day ago

Europe’s Drought Crisis Deepens as EU Pushes New Water Resilience Measures

Europe’s worsening drought is disrupting agriculture, transport, ecosystems and water supplies as extreme heat intensifies… Read More

3 days ago

Jellyfish Force Shutdown of Three Reactors at French Nuclear Plant

A swarm of jellyfish has disrupted operations at France’s largest nuclear site, forcing three reactors… Read More

3 days ago

This website uses cookies.