Up to 19 million citizens
Poland is facing a potential public health data crisis following reports of a massive data breach at MyDr, the country's main healthcare platform. According to a report from Check Point Research on August 17, 2026, unidentified attackers claim to have exfiltrated 2.5 terabytes of data, potentially impacting nearly 19 million Polish citizens. The stolen data is said to include extremely sensitive information such as medical records, prescriptions, and personal identification details. The threat actors substantiated their claim by leaking the data of a senior Polish politician. This incident represents a catastrophic privacy failure, exposing a significant portion of the population to severe risks including blackmail, fraud, and targeted social engineering.
The attack targeted MyDr, a central digital platform in Poland's healthcare system used for managing medical appointments, electronic health records (EHR), and e-prescriptions. An unknown threat actor or group claims to have successfully breached the platform's infrastructure and stolen a colossal 2.5 TB of data. The scale of the breach is staggering, with a potential impact on up to 19 million people, which is roughly half of Poland's population.
To demonstrate the validity of their claims and apply pressure, the attackers leaked a sample of the stolen data. This sample included the personal identification number (PESEL), phone number, and prescription details of a high-profile Polish politician. This act confirms the authenticity of the breach and the sensitive nature of the compromised information. The attackers' ultimate motive is not yet clear; they could be preparing to sell the data on cybercrime forums, ransom the data back to MyDr or the Polish government, or leak it publicly for political or ideological reasons.
The technical details of how the attackers breached MyDr have not been disclosed. However, a breach of this scale involving a large database suggests several potential vectors:
T1530 - Data from Cloud Storage Object: A highly likely technique if the 2.5 TB of data was stored in a misconfigured cloud environment.T1213 - Data from Information Repositories: The core of the attack, where actors accessed and stole data from the platform's primary database.T1003 - OS Credential Dumping: If initial access was gained to a server, attackers could have dumped credentials to escalate privileges and access the database.T1020 - Automated Exfiltration: Exfiltrating 2.5 TB of data requires an automated and sustained effort.The compromise of a national healthcare database is one of the worst-case scenarios in cybersecurity. The impact is severe and widespread:
No specific technical indicators of compromise were provided in the source articles.
For operators of critical national databases like MyDr:
Implement strong, application-level or transparent data encryption (TDE) for the database to protect sensitive health records even if the storage is compromised.
Deploy Data Loss Prevention (DLP) and network monitoring solutions to detect and block large, anomalous outbound data transfers.
Strictly control and monitor access to administrative and database accounts. Use just-in-time access and require MFA.
For cloud-based storage, use Cloud Security Posture Management (CSPM) to continuously audit for and remediate misconfigurations like public storage buckets.
To detect and prevent a catastrophic data breach like the one at MyDr, implementing User Data Transfer Analysis is essential. This involves deploying a Data Loss Prevention (DLP) or network analysis tool capable of monitoring the volume of data leaving the network perimeter. A baseline for normal egress traffic volume must be established. A rule should then be created to trigger a high-severity alert and potentially block traffic if the outbound data volume from the database or application servers exceeds this baseline by a significant margin over a specific time window. Exfiltrating 2.5 TB of data is not a subtle event; it's a massive, sustained data flow that is easily detectable with the right monitoring. This technique acts as a last line of defense to prevent the theft of data even after an initial compromise.
Protecting the sensitive medical records of 19 million citizens requires robust encryption at all stages. For the MyDr platform, this means going beyond standard disk encryption. The database itself should utilize Transparent Data Encryption (TDE) to encrypt the data files at rest. Furthermore, specific columns containing highly sensitive information (like medical diagnoses or national ID numbers) should be encrypted at the application layer before being written to the database, using a key managed in a separate, secure Hardware Security Module (HSM). This defense-in-depth approach ensures that even if an attacker compromises the server and exfiltrates the database files (as likely happened here), the most sensitive data remains encrypted and unusable to them, dramatically reducing the impact of the breach.
Check Point Research reports the massive data breach at MyDr, noting attackers claim to have 2.5TB of data and have leaked a sample.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.