Major Data Breach at Polish Healthcare Platform MyDr

Polish Healthcare Platform 'MyDr' Suffers Major Breach Affecting Millions

CRITICAL
August 17, 2026
5m read
Data BreachCyberattackRegulatory

Impact Scope

People Affected

Up to 19 million citizens

Industries Affected

Healthcare

Geographic Impact

Poland (national)

Related Entities

Organizations

Other

MyDrPoland

Full Report

Executive Summary

Poland is facing a potential public health data crisis following reports of a massive data breach at MyDr, the country's main healthcare platform. According to a report from Check Point Research on August 17, 2026, unidentified attackers claim to have exfiltrated 2.5 terabytes of data, potentially impacting nearly 19 million Polish citizens. The stolen data is said to include extremely sensitive information such as medical records, prescriptions, and personal identification details. The threat actors substantiated their claim by leaking the data of a senior Polish politician. This incident represents a catastrophic privacy failure, exposing a significant portion of the population to severe risks including blackmail, fraud, and targeted social engineering.

Threat Overview

The attack targeted MyDr, a central digital platform in Poland's healthcare system used for managing medical appointments, electronic health records (EHR), and e-prescriptions. An unknown threat actor or group claims to have successfully breached the platform's infrastructure and stolen a colossal 2.5 TB of data. The scale of the breach is staggering, with a potential impact on up to 19 million people, which is roughly half of Poland's population.

To demonstrate the validity of their claims and apply pressure, the attackers leaked a sample of the stolen data. This sample included the personal identification number (PESEL), phone number, and prescription details of a high-profile Polish politician. This act confirms the authenticity of the breach and the sensitive nature of the compromised information. The attackers' ultimate motive is not yet clear; they could be preparing to sell the data on cybercrime forums, ransom the data back to MyDr or the Polish government, or leak it publicly for political or ideological reasons.

Technical Analysis

The technical details of how the attackers breached MyDr have not been disclosed. However, a breach of this scale involving a large database suggests several potential vectors:

  • Vulnerable Application: A critical, unpatched vulnerability in the MyDr web application or its APIs could have allowed for unauthorized access and data exfiltration.
  • Cloud Misconfiguration: If the data was stored in a cloud environment, a misconfigured storage bucket (e.g., a public S3 bucket) could have left the 2.5 TB of data exposed.
  • Credential Compromise: Stolen credentials for a privileged administrator or database account could have granted the attackers direct access to the data.
  • Insider Threat: The possibility of a malicious insider cannot be ruled out.

MITRE ATT&CK Techniques (Assessed)

Impact Assessment

The compromise of a national healthcare database is one of the worst-case scenarios in cybersecurity. The impact is severe and widespread:

  • Extreme Privacy Violation: The data includes intimate details of citizens' health conditions, treatments, and medications. Its exposure is a massive violation of personal privacy.
  • Blackmail and Extortion: Individuals, especially public figures or those with sensitive medical conditions, could be targeted for blackmail.
  • Targeted Fraud and Phishing: Scammers can use the detailed personal and medical information to create highly convincing phishing campaigns or fraudulent schemes (e.g., "Your prescription is expiring, click here to renew").
  • National Security and Social Unrest: The leak of a politician's data suggests a potential political motive. A mass leak could be used to sow social discord or undermine trust in the government and public institutions.
  • Regulatory Penalties: The breach is a major violation of GDPR, which will likely result in a substantial fine for the platform operator.

IOCs — Directly from Articles

No specific technical indicators of compromise were provided in the source articles.

Detection & Response

  • Data Leakage Detection: Security firms and government agencies will be monitoring dark web forums and marketplaces for the sale or leak of this dataset.
  • Forensic Investigation: A full investigation is required to understand the initial access vector, the extent of the breach, and the timeline of the attacker's activity.
  • Public Notification: A clear and transparent communication plan is needed to inform the Polish public about the risks and provide guidance on how to protect themselves.

Mitigation

For operators of critical national databases like MyDr:

  • Assume a Hostile Environment: Treat the platform as a prime target for nation-state and high-level cybercrime groups.
  • Robust Security Architecture: Implement a defense-in-depth strategy, including network segmentation, strict access controls, and end-to-end encryption.
  • Continuous Vulnerability Management: Conduct regular penetration testing, vulnerability scanning, and code reviews to identify and remediate flaws before they can be exploited.
  • Data Loss Prevention (DLP): Deploy DLP solutions to monitor for and block large, unauthorized data transfers leaving the network.
  • Cloud Security Posture Management (CSPM): If using cloud infrastructure, use CSPM tools to continuously scan for and remediate misconfigurations.

Timeline of Events

1
August 17, 2026
Check Point Research reports the massive data breach at MyDr, noting attackers claim to have 2.5TB of data and have leaked a sample.
2
August 17, 2026
This article was published

MITRE ATT&CK Mitigations

Implement strong, application-level or transparent data encryption (TDE) for the database to protect sensitive health records even if the storage is compromised.

Deploy Data Loss Prevention (DLP) and network monitoring solutions to detect and block large, anomalous outbound data transfers.

Strictly control and monitor access to administrative and database accounts. Use just-in-time access and require MFA.

For cloud-based storage, use Cloud Security Posture Management (CSPM) to continuously audit for and remediate misconfigurations like public storage buckets.

D3FEND Defensive Countermeasures

To detect and prevent a catastrophic data breach like the one at MyDr, implementing User Data Transfer Analysis is essential. This involves deploying a Data Loss Prevention (DLP) or network analysis tool capable of monitoring the volume of data leaving the network perimeter. A baseline for normal egress traffic volume must be established. A rule should then be created to trigger a high-severity alert and potentially block traffic if the outbound data volume from the database or application servers exceeds this baseline by a significant margin over a specific time window. Exfiltrating 2.5 TB of data is not a subtle event; it's a massive, sustained data flow that is easily detectable with the right monitoring. This technique acts as a last line of defense to prevent the theft of data even after an initial compromise.

Protecting the sensitive medical records of 19 million citizens requires robust encryption at all stages. For the MyDr platform, this means going beyond standard disk encryption. The database itself should utilize Transparent Data Encryption (TDE) to encrypt the data files at rest. Furthermore, specific columns containing highly sensitive information (like medical diagnoses or national ID numbers) should be encrypted at the application layer before being written to the database, using a key managed in a separate, secure Hardware Security Module (HSM). This defense-in-depth approach ensures that even if an attacker compromises the server and exfiltrates the database files (as likely happened here), the most sensitive data remains encrypted and unusable to them, dramatically reducing the impact of the breach.

Timeline of Events

1
August 17, 2026

Check Point Research reports the massive data breach at MyDr, noting attackers claim to have 2.5TB of data and have leaked a sample.

Sources & References

17th August – Threat Intelligence Report
Check Point Research (checkpoint.com) August 17, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachHealthcareMyDrPolandCheck PointGDPREHR

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.