Major Data Breach at Polish Healthcare Platform MyDr

Polish Healthcare Platform 'MyDr' Suffers Major Breach Affecting Millions

CRITICAL
August 17, 2026
August 18, 2026
m read
Data BreachCyberattackRegulatory

Impact Scope

People Affected

Up to 19 million citizens

Industries Affected

Healthcare

Geographic Impact

Poland (national)

Related Entities(initial)

Organizations

Check Point Research

Other

MyDrPoland

Full Report(when first published)

Executive Summary

Poland is facing a potential public health data crisis following reports of a massive data breach at MyDr, the country's main healthcare platform. According to a report from Check Point Research on August 17, 2026, unidentified attackers claim to have exfiltrated 2.5 terabytes of data, potentially impacting nearly 19 million Polish citizens. The stolen data is said to include extremely sensitive information such as medical records, prescriptions, and personal identification details. The threat actors substantiated their claim by leaking the data of a senior Polish politician. This incident represents a catastrophic privacy failure, exposing a significant portion of the population to severe risks including blackmail, fraud, and targeted social engineering.

Threat Overview

The attack targeted MyDr, a central digital platform in Poland's healthcare system used for managing medical appointments, electronic health records (EHR), and e-prescriptions. An unknown threat actor or group claims to have successfully breached the platform's infrastructure and stolen a colossal 2.5 TB of data. The scale of the breach is staggering, with a potential impact on up to 19 million people, which is roughly half of Poland's population.

To demonstrate the validity of their claims and apply pressure, the attackers leaked a sample of the stolen data. This sample included the personal identification number (PESEL), phone number, and prescription details of a high-profile Polish politician. This act confirms the authenticity of the breach and the sensitive nature of the compromised information. The attackers' ultimate motive is not yet clear; they could be preparing to sell the data on cybercrime forums, ransom the data back to MyDr or the Polish government, or leak it publicly for political or ideological reasons.

Technical Analysis

The technical details of how the attackers breached MyDr have not been disclosed. However, a breach of this scale involving a large database suggests several potential vectors:

  • Vulnerable Application: A critical, unpatched vulnerability in the MyDr web application or its APIs could have allowed for unauthorized access and data exfiltration.
  • Cloud Misconfiguration: If the data was stored in a cloud environment, a misconfigured storage bucket (e.g., a public S3 bucket) could have left the 2.5 TB of data exposed.
  • Credential Compromise: Stolen credentials for a privileged administrator or database account could have granted the attackers direct access to the data.
  • Insider Threat: The possibility of a malicious insider cannot be ruled out.

MITRE ATT&CK Techniques (Assessed)

Impact Assessment

The compromise of a national healthcare database is one of the worst-case scenarios in cybersecurity. The impact is severe and widespread:

  • Extreme Privacy Violation: The data includes intimate details of citizens' health conditions, treatments, and medications. Its exposure is a massive violation of personal privacy.
  • Blackmail and Extortion: Individuals, especially public figures or those with sensitive medical conditions, could be targeted for blackmail.
  • Targeted Fraud and Phishing: Scammers can use the detailed personal and medical information to create highly convincing phishing campaigns or fraudulent schemes (e.g., "Your prescription is expiring, click here to renew").
  • National Security and Social Unrest: The leak of a politician's data suggests a potential political motive. A mass leak could be used to sow social discord or undermine trust in the government and public institutions.
  • Regulatory Penalties: The breach is a major violation of GDPR, which will likely result in a substantial fine for the platform operator.

IOCs — Directly from Articles

No specific technical indicators of compromise were provided in the source articles.

Detection & Response

  • Data Leakage Detection: Security firms and government agencies will be monitoring dark web forums and marketplaces for the sale or leak of this dataset.
  • Forensic Investigation: A full investigation is required to understand the initial access vector, the extent of the breach, and the timeline of the attacker's activity.
  • Public Notification: A clear and transparent communication plan is needed to inform the Polish public about the risks and provide guidance on how to protect themselves.

Mitigation

For operators of critical national databases like MyDr:

  • Assume a Hostile Environment: Treat the platform as a prime target for nation-state and high-level cybercrime groups.
  • Robust Security Architecture: Implement a defense-in-depth strategy, including network segmentation, strict access controls, and end-to-end encryption.
  • Continuous Vulnerability Management: Conduct regular penetration testing, vulnerability scanning, and code reviews to identify and remediate flaws before they can be exploited.
  • Data Loss Prevention (DLP): Deploy DLP solutions to monitor for and block large, unauthorized data transfers leaving the network.
  • Cloud Security Posture Management (CSPM): If using cloud infrastructure, use CSPM tools to continuously scan for and remediate misconfigurations.

Timeline of Events

1
August 17, 2026
Check Point Research reports the massive data breach at MyDr, noting attackers claim to have 2.5TB of data and have leaked a sample.
2
August 17, 2026
This article was published

Article Updates

August 18, 2026

Polish authorities launch investigation into MyDr breach; e-Health Center rotates digital certificates as a precaution.

Polish authorities, including the Personal Data Protection Office, have initiated a full-scale investigation into the MyDr breach. As a precautionary measure, the national e-Health Center has begun rotating digital certificates for medical systems. The Polish Prime Minister suggested a potential ransom motive, while MyDr confirmed 'external, intentional criminal activity.' The updated analysis also details potential attack vectors like compromised credentials (T1078) and vulnerability exploitation (T1190), and provides new cyber observables and mitigation strategies, including D3FEND links for cloud security posture management and access controls.

Timeline of Events

1
August 17, 2026

Check Point Research reports the massive data breach at MyDr, noting attackers claim to have 2.5TB of data and have leaked a sample.

Sources & References(when first published)

17th August – Threat Intelligence Report
research.checkpoint.com•August 17, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Check PointData BreachEHRGDPRHealthcareMyDrPoland

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.