Polish medical records system breached: extortionists claim 18.8 million patients
Attackers say they pulled 2.5 terabytes out of MyDr, one of the largest suppliers of electronic medical records software in Poland, and that the haul contains 18,814,422 unique PESEL numbers, the Polish national identifier. That is about half the country. The company confirms an incident and says it is establishing the scope; it does not confirm a theft. The deputy prime minister in charge of digital affairs says services are checking the circumstances.
How it surfaced
On Saturday someone contacted the Polish security outlet Zaufana Trzecia Strona claiming to hold data on more than 18 million people taken from medical systems. The outlet took it seriously, spoke to the source directly and notified the institutions. What it published next is the part that matters, because it is the only independent check anyone has been able to run so far.
The proof offered was a screenshot of database entries for one of Poland's most prominent politicians: correct date of birth, PESEL, full name and two phone numbers, one of which the journalists confirmed from other sources. The record listed the right regional health fund branch. It came with a prescription for a specific medicine, which nobody outside the system can verify. The attackers also sent the article author's own record: the PESEL matched, the health fund region matched, and the phone field held 111111111, the placeholder clinics type in when they cannot be bothered.
Extortion dressed as an audit
The attackers also showed a message they say they sent on 5 August to the chief executive of the company that owns the platform. It linked to a PDF that was supposed to self destruct after download and did not: the journalists opened the same link days later. The file was password protected, and the password was the executive's own PESEL, which took no effort to guess. Inside was the same evidence and a request to get in touch, with the whole thing framed as an offer to buy the results of a security audit.
Two things follow from that detail. The extortion is professional in form and amateur in operational security, and the identifier at the centre of this story is so predictable that it was used as a password by the person whose company is meant to protect it.
What is confirmed and what is not
Claimed by the attackers
- 2.5 TB downloaded from the servers
- 18.8 million unique PESEL numbers
- Prescriptions and patient records included
Confirmed so far
- MyDr reports a security incident and has gone to law enforcement
- Sample records checked by journalists matched real people
- The full volume and the source of the data are not verified
Why a medical record is worse than a password
A password is a token you can replace in a minute. A PESEL is issued once, and the illness behind a prescription is not a credential at all, it is a fact about a person. A leaked pair of national identifier and prescription history gives a stranger two things at once: enough to impersonate you at an institution, and enough to pressure you quietly.
Prescriptions are the sharp end of it. A single line of a drug name can reveal a psychiatric diagnosis, an HIV status, a pregnancy termination, an addiction treatment. In a normal year that information is protected by professional secrecy; in a bad week it becomes a row in a database being shopped around.
One vendor, thousands of clinics
The uncomfortable structure is familiar from every large leak. Doctors do not run their own databases: they type into the system their clinic bought, and thousands of clinics buy the same few systems. That is efficient, and it means a single supplier holds the medical histories of half a country. MyDr belongs to the ZnanyLekarz group, itself part of DocPlanner, a company operating in over a dozen countries, which is why an incident at one Polish product is being read carefully well beyond Poland. Nothing so far indicates data from other countries is involved.
Concentration is not a mistake anyone made on purpose. It is what happens when a market consolidates, and it turns every supplier breach into a national event.
What a person in Poland can do today
- Freeze your PESEL through the mObywatel app or gov.pl. Since June 2024 banks must check the register before granting a loan, so a frozen number blocks credit taken in your name. It can be lifted for a moment when you genuinely need it.
- Expect phishing that knows your medical details. A caller who names your clinic, your doctor and a real prescription is far more convincing than the usual bank scam.
- Never confirm data over the phone because the caller already said part of it. Hang up and call the institution back on a number you looked up yourself.
- Watch bank notifications and credit checks for a few months. Identity theft using a leaked national ID usually shows up as an application you did not make.
A VPN is not the tool here
Worth saying plainly, because privacy tools get mentioned reflexively after every leak. A VPN protects data in transit between you and a service. This data was taken from the other end, from the systems where clinics store it, and no setting on your phone could have changed that. What helps is on the institutional side: how the vendor stores records, how quickly it tells people, and what the regulator does afterwards.
• Hakerzy twierdzą, że ukradli dane ponad 18 milionów Polek i Polaków z firmy MyDr - Zaufana Trzecia Strona
• Cyberatak na MyDr. Hakerzy ogłosili, że wykradli PESEL-e ponad 18 mln Polaków - CRN
• Mieli wykraść dane medyczne blisko 19 mln Polaków. Gigantyczny atak pod lupą służb - Rynek Zdrowia
• Zastrzeż swój numer PESEL lub cofnij zastrzeżenie - Gov.pl