Poland Investigates MyDr Healthcare Data Breach

Poland Probes Massive MyDr Healthcare Data Breach

CRITICAL
August 18, 2026
August 20, 2026
5m read
Data BreachCyberattackRegulatory

Impact Scope

People Affected

Nearly 19 million

Industries Affected

Healthcare

Geographic Impact

Poland (national)

Related Entities(initial)

Organizations

e-Health Center (Poland)Polish Personal Data Protection Office

Other

MyDrPoland

Full Report(when first published)

Executive Summary

Poland is facing one of the largest data breaches in its history following a major cyberattack on MyDr, a widely used primary healthcare software platform. The breach may have exposed the personal and medical data of nearly 19 million Polish citizens. Attackers claim to have exfiltrated 2.5 terabytes of data from the company's cloud infrastructure and have substantiated their claims by leaking the sensitive information of a Polish politician. The compromised data reportedly includes names, national identification numbers (PESEL), prescriptions, and other medical records. Polish authorities, including the Personal Data Protection Office, have launched a full-scale investigation, and the national e-Health Center has begun rotating digital certificates for medical systems as a precaution.

Threat Overview

The attack targets MyDr, a software provider for over 12,000 clinics and medical practices across Poland, which manages electronic medical records, appointments, and prescriptions. The attackers, whose identity remains unknown, claim to have stolen 2.5TB of data from MyDr's systems, covering records up to April 2024. To demonstrate the validity of their breach, they provided journalists with a politician's PESEL number, phone number, and 25 recent prescriptions.

The Polish Prime Minister has suggested the attack may have been an attempt to extort a ransom. While MyDr has confirmed the 'external, intentional criminal activity' and stated it has secured its systems, the potential scale of the breach is staggering, potentially affecting a significant portion of the Polish population. In response to the incident, Poland's e-Health Center has initiated the replacement of digital certificates used by medical facilities to connect to the national P1 e-health platform, even though there is no direct evidence the certificates themselves were stolen.

Technical Analysis

While the exact method of the breach has not been disclosed, the theft of 2.5TB of data from a cloud environment points to several potential attack vectors:

  1. Misconfigured Cloud Storage (T1530): A common vector for large-scale data theft is an improperly secured cloud storage bucket (e.g., AWS S3, Azure Blob Storage) that is either publicly accessible or has weak access controls.
  2. Compromised Credentials (T1078): Attackers may have obtained credentials for a privileged account (e.g., a developer or cloud administrator) through phishing, password spraying, or from a previous breach.
  3. Vulnerability Exploitation (T1190): An unpatched vulnerability in a public-facing application or API connected to the cloud infrastructure could have provided the initial entry point for the attackers to access and exfiltrate the data.
  4. Data Exfiltration (T1567): The large volume of data was likely exfiltrated over an extended period or through a high-bandwidth channel. Attackers often use legitimate cloud services or custom tools to transfer large datasets to avoid detection.

Impact Assessment

The potential impact of this breach is immense. The exposure of highly sensitive personal and medical data for 19 million people could lead to widespread identity theft, fraud, and targeted phishing or blackmail campaigns against individuals, including high-profile figures like politicians. The leak of prescription and medical history data is a profound violation of privacy with long-lasting consequences. For the Polish state, this represents a major national security incident, eroding public trust in digital healthcare initiatives. MyDr faces catastrophic reputational damage, legal liability, and significant regulatory fines under GDPR. The incident could have a chilling effect on the adoption of digital health services in the country.

IOCs — Directly from Articles

No specific Indicators of Compromise were provided in the source articles.

Cyber Observables — Hunting Hints

For cloud security teams, hunting for similar threats involves:

Type
Log Source
Value
Cloud Trail / Audit Logs
Description
Look for anomalous API calls, such as s3:GetObject or ListBuckets from unusual IP addresses or user agents.
Type
Network Traffic Pattern
Value
Large Egress Data Transfer
Description
Monitor for unusually large data transfers from cloud storage or databases to external IP addresses.
Type
User Account Pattern
Value
Dormant or service accounts suddenly showing high activity.
Description
A compromised account may be used for reconnaissance and exfiltration.
Type
API Endpoint
Value
Unprotected or unauthenticated public API endpoints.
Description
Regularly scan for APIs that return sensitive data without proper authorization checks.

Detection & Response

  • Cloud Security Posture Management (CSPM): Use CSPM tools to continuously scan cloud environments for misconfigurations, such as public storage buckets or overly permissive IAM roles.
  • Data Loss Prevention (DLP): Implement DLP solutions that can detect and block the exfiltration of large volumes of sensitive data, identified by patterns like PESEL numbers or medical terminology.
  • Threat Intelligence: Monitor dark web forums and threat intelligence feeds for any mention of your organization's data or infrastructure, which could provide an early warning of a breach.
  • Identity and Access Management (IAM) Auditing: Regularly audit cloud IAM roles and permissions. Alert on unusual activity, such as a user accessing data they have never accessed before. D3FEND's Domain Account Monitoring is relevant here.

Mitigation

  • Cloud Configuration Hardening: The most critical mitigation is to ensure all cloud resources are securely configured. This includes making all storage buckets private by default, enforcing encryption at rest and in transit, and using network access control lists. This aligns with D3FEND's Application Configuration Hardening.
  • Strong Access Controls: Enforce the principle of least privilege for all cloud accounts and services. Use multi-factor authentication (MFA) for all administrative access.
  • Data Minimization: Only collect and store the data that is absolutely necessary. Anonymize or pseudonymize data where possible to reduce the impact of a potential breach.
  • Regular Security Audits: Conduct regular, independent security audits and penetration tests of cloud infrastructure to identify and remediate weaknesses before they can be exploited.

Timeline of Events

1
April 30, 2024
The breached data reportedly includes records up to this date.
2
August 14, 2026
Reports of the massive data breach begin to surface, with attackers leaking politician's data.
3
August 17, 2026
Polish authorities confirm they are probing the incident, described as one of the largest in the country's history.
4
August 18, 2026
This article was published

Article Updates

August 20, 2026

MyDr breach update: Medical consultation notes, diagnosed diseases, and email addresses confirmed exposed. Polish data protection authority plans formal inspection.

MITRE ATT&CK Mitigations

Implement and enforce secure configurations for all cloud services, especially storage, to prevent unauthorized public access.

Mapped D3FEND Techniques:

Strictly control and monitor privileged accounts in the cloud environment, enforcing MFA and the principle of least privilege.

Mapped D3FEND Techniques:

Enable and regularly review cloud audit logs (e.g., CloudTrail) to detect suspicious activity related to data access and exfiltration.

Mapped D3FEND Techniques:

Encrypt all sensitive data at rest and in transit. Consider application-level encryption for highly sensitive data to add another layer of protection.

Mapped D3FEND Techniques:

D3FEND Defensive Countermeasures

The MyDr breach underscores the catastrophic potential of cloud misconfigurations. The primary defensive measure is rigorous Application Configuration Hardening, specifically for cloud storage and databases. Security teams must implement a 'private-by-default' policy for all cloud storage resources like AWS S3 buckets or Azure Blobs. This should be enforced through automated guardrails using Cloud Security Posture Management (CSPM) tools that continuously scan for and auto-remediate public-facing storage. Access should be granted only through strict IAM policies that adhere to the principle of least privilege. For a healthcare platform like MyDr, this means that even internal developers should not have direct, unfettered access to production data. All access should be temporary, role-based, and logged. This prevents the kind of bulk data exfiltration seen in this incident.

To detect an attack like the one on MyDr in progress, organizations need robust User Data Transfer Analysis. It's not enough to just log access; you must analyze the patterns of that access. A system should be in place to baseline normal data access patterns and alert on significant deviations. For example, a developer account that suddenly starts downloading terabytes of data, or access from a previously unseen IP address or region, should trigger an immediate, high-priority alert. Implementing a Data Loss Prevention (DLP) solution that understands cloud environments can automate this. Such a system would analyze egress traffic from cloud storage and databases, identify sensitive data patterns (like PESEL numbers), and either block the transfer or alert security teams when a predefined threshold is exceeded. This can turn a multi-terabyte breach into a detected and stopped attempt.

Timeline of Events

1
April 30, 2024

The breached data reportedly includes records up to this date.

2
August 14, 2026

Reports of the massive data breach begin to surface, with attackers leaking politician's data.

3
August 17, 2026

Polish authorities confirm they are probing the incident, described as one of the largest in the country's history.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachHealthcarePolandMyDrGDPRCloud Security

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.