Up to 19 million citizens
Poland is facing a potential public health data crisis following reports of a massive data breach at MyDr, the country's main healthcare platform. According to a report from Check Point Research on August 17, 2026, unidentified attackers claim to have exfiltrated 2.5 terabytes of data, potentially impacting nearly 19 million Polish citizens. The stolen data is said to include extremely sensitive information such as medical records, prescriptions, and personal identification details. The threat actors substantiated their claim by leaking the data of a senior Polish politician. This incident represents a catastrophic privacy failure, exposing a significant portion of the population to severe risks including blackmail, fraud, and targeted social engineering.
The attack targeted MyDr, a central digital platform in Poland's healthcare system used for managing medical appointments, electronic health records (EHR), and e-prescriptions. An unknown threat actor or group claims to have successfully breached the platform's infrastructure and stolen a colossal 2.5 TB of data. The scale of the breach is staggering, with a potential impact on up to 19 million people, which is roughly half of Poland's population.
To demonstrate the validity of their claims and apply pressure, the attackers leaked a sample of the stolen data. This sample included the personal identification number (PESEL), phone number, and prescription details of a high-profile Polish politician. This act confirms the authenticity of the breach and the sensitive nature of the compromised information. The attackers' ultimate motive is not yet clear; they could be preparing to sell the data on cybercrime forums, ransom the data back to MyDr or the Polish government, or leak it publicly for political or ideological reasons.
The technical details of how the attackers breached MyDr have not been disclosed. However, a breach of this scale involving a large database suggests several potential vectors:
T1530 - Data from Cloud Storage Object: A highly likely technique if the 2.5 TB of data was stored in a misconfigured cloud environment.T1213 - Data from Information Repositories: The core of the attack, where actors accessed and stole data from the platform's primary database.T1003 - OS Credential Dumping: If initial access was gained to a server, attackers could have dumped credentials to escalate privileges and access the database.T1020 - Automated Exfiltration: Exfiltrating 2.5 TB of data requires an automated and sustained effort.The compromise of a national healthcare database is one of the worst-case scenarios in cybersecurity. The impact is severe and widespread:
No specific technical indicators of compromise were provided in the source articles.
For operators of critical national databases like MyDr:
Polish authorities launch investigation into MyDr breach; e-Health Center rotates digital certificates as a precaution.
Polish authorities, including the Personal Data Protection Office, have initiated a full-scale investigation into the MyDr breach. As a precautionary measure, the national e-Health Center has begun rotating digital certificates for medical systems. The Polish Prime Minister suggested a potential ransom motive, while MyDr confirmed 'external, intentional criminal activity.' The updated analysis also details potential attack vectors like compromised credentials (T1078) and vulnerability exploitation (T1190), and provides new cyber observables and mitigation strategies, including D3FEND links for cloud security posture management and access controls.
Check Point Research reports the massive data breach at MyDr, noting attackers claim to have 2.5TB of data and have leaked a sample.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.