← MyDr

2026 MyDr (Poland) — minister/company confirm ~19M records stolen (~2TB medical data)

2026 19.0M records affected Share on X

Data compromised

Company/minister: ~19 million records (~2TB) with linkable fragments including PESEL-adjacent identity, prescriptions, scheduled appointments, prescribed medications, and documents patients presented to doctors. Actor earlier cited 18,814,422 unique PESELs. ~12,000 medical facilities notified per press.

Technical writeup

Government- and company-confirmed mega-breach — On August 12, 2026 Digital Affairs Minister (and deputy PM) Krzysztof Gawkowski told a press conference that an “extraordinary” / “unprecedented” leak from the MyDr electronic patient-records platform affected nearly 19 million people. Gawkowski said the company itself confirmed about 19 million records were stolen—various linkable data types totaling more than 2 terabytes—including medical-history material such as prescriptions, appointments, medications, and documents patients presented to doctors. Press cites roughly 12,000 medical facilities being notified while systems continue to operate; the Central Cybercrime Bureau is investigating. Authorities reported no indications of a foreign-state attack at the briefing and advised citizens to reserve/block PESEL via mObywatel and that a check mechanism would be made available. Earlier (Aug 10), Zaufana Trzecia Strona reported actors claiming 18,814,422 unique PESELs and ~2.5 TB after Aug 5 extortion outreach; MyDr had already posted an investigation notice. BreachHistory updates recordsAffected to 19000000 reflecting the minister/company confirmation (superseding the prior actor-only framing of the count).

Root cause

Confirmed theft of MyDr EMR patient data (company + Digital Affairs Minister Krzysztof Gawkowski, Aug 12 press conference). Technical intrusion path not yet published; no nation-state attribution indicated.

References