Nearly 19 million
Poland is facing one of the largest data breaches in its history following a major cyberattack on MyDr, a widely used primary healthcare software platform. The breach may have exposed the personal and medical data of nearly 19 million Polish citizens. Attackers claim to have exfiltrated 2.5 terabytes of data from the company's cloud infrastructure and have substantiated their claims by leaking the sensitive information of a Polish politician. The compromised data reportedly includes names, national identification numbers (PESEL), prescriptions, and other medical records. Polish authorities, including the Personal Data Protection Office, have launched a full-scale investigation, and the national e-Health Center has begun rotating digital certificates for medical systems as a precaution.
The attack targets MyDr, a software provider for over 12,000 clinics and medical practices across Poland, which manages electronic medical records, appointments, and prescriptions. The attackers, whose identity remains unknown, claim to have stolen 2.5TB of data from MyDr's systems, covering records up to April 2024. To demonstrate the validity of their breach, they provided journalists with a politician's PESEL number, phone number, and 25 recent prescriptions.
The Polish Prime Minister has suggested the attack may have been an attempt to extort a ransom. While MyDr has confirmed the 'external, intentional criminal activity' and stated it has secured its systems, the potential scale of the breach is staggering, potentially affecting a significant portion of the Polish population. In response to the incident, Poland's e-Health Center has initiated the replacement of digital certificates used by medical facilities to connect to the national P1 e-health platform, even though there is no direct evidence the certificates themselves were stolen.
While the exact method of the breach has not been disclosed, the theft of 2.5TB of data from a cloud environment points to several potential attack vectors:
The potential impact of this breach is immense. The exposure of highly sensitive personal and medical data for 19 million people could lead to widespread identity theft, fraud, and targeted phishing or blackmail campaigns against individuals, including high-profile figures like politicians. The leak of prescription and medical history data is a profound violation of privacy with long-lasting consequences. For the Polish state, this represents a major national security incident, eroding public trust in digital healthcare initiatives. MyDr faces catastrophic reputational damage, legal liability, and significant regulatory fines under GDPR. The incident could have a chilling effect on the adoption of digital health services in the country.
No specific Indicators of Compromise were provided in the source articles.
For cloud security teams, hunting for similar threats involves:
s3:GetObject or ListBuckets from unusual IP addresses or user agents.MyDr breach update: Medical consultation notes, diagnosed diseases, and email addresses confirmed exposed. Polish data protection authority plans formal inspection.
Implement and enforce secure configurations for all cloud services, especially storage, to prevent unauthorized public access.
Mapped D3FEND Techniques:
Strictly control and monitor privileged accounts in the cloud environment, enforcing MFA and the principle of least privilege.
Enable and regularly review cloud audit logs (e.g., CloudTrail) to detect suspicious activity related to data access and exfiltration.
Mapped D3FEND Techniques:
Encrypt all sensitive data at rest and in transit. Consider application-level encryption for highly sensitive data to add another layer of protection.
Mapped D3FEND Techniques:
The MyDr breach underscores the catastrophic potential of cloud misconfigurations. The primary defensive measure is rigorous Application Configuration Hardening, specifically for cloud storage and databases. Security teams must implement a 'private-by-default' policy for all cloud storage resources like AWS S3 buckets or Azure Blobs. This should be enforced through automated guardrails using Cloud Security Posture Management (CSPM) tools that continuously scan for and auto-remediate public-facing storage. Access should be granted only through strict IAM policies that adhere to the principle of least privilege. For a healthcare platform like MyDr, this means that even internal developers should not have direct, unfettered access to production data. All access should be temporary, role-based, and logged. This prevents the kind of bulk data exfiltration seen in this incident.
To detect an attack like the one on MyDr in progress, organizations need robust User Data Transfer Analysis. It's not enough to just log access; you must analyze the patterns of that access. A system should be in place to baseline normal data access patterns and alert on significant deviations. For example, a developer account that suddenly starts downloading terabytes of data, or access from a previously unseen IP address or region, should trigger an immediate, high-priority alert. Implementing a Data Loss Prevention (DLP) solution that understands cloud environments can automate this. Such a system would analyze egress traffic from cloud storage and databases, identify sensitive data patterns (like PESEL numbers), and either block the transfer or alert security teams when a predefined threshold is exceeded. This can turn a multi-terabyte breach into a detected and stopped attempt.
The breached data reportedly includes records up to this date.
Reports of the massive data breach begin to surface, with attackers leaking politician's data.
Polish authorities confirm they are probing the incident, described as one of the largest in the country's history.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.