Polish authorities are investigating a cyberattack on healthcare software provider MyDr that may have exposed historical data tied to nearly 19 million people and more than 12,000 medical facilities. Prime Minister Donald Tusk said the breach was intended to extort a ransom, while officials stressed there is no indication that Poland’s public healthcare systems or the national P1 electronic health platform were compromised. MyDr said it identified and removed the source of the incident, introduced additional security measures, and had found no evidence that the stolen data had been publicly released.
As a precaution, Poland’s e-Health Center is replacing digital certificates used by medical systems to connect to the P1 platform, even though authorities said there is no evidence the certificates were stolen or abused. Regulators and security agencies are continuing to investigate the scope of the breach and identify those responsible, as the incident raises concern over the exposure of sensitive healthcare records and operational data across the country’s medical sector.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
Polish authorities said hackers obtained unauthorized access to historical data held in MyDr systems, with the exposed data spanning through April 2024. The incident may have affected nearly 19 million people and more than 12,000 medical facilities, though officials said not all customers or patients were necessarily impacted.
Poland's e-Health Center started replacing digital certificates used by medical systems to connect to the national P1 electronic health platform. Officials said there was no evidence the certificates were stolen or misused, and that the replacement should not disrupt services such as e-prescriptions and referrals.
Polish authorities began investigating the cyberattack against MyDr, while the Personal Data Protection Office said it planned to inspect the company. Security agencies are also working to identify those responsible, and officials said MyDr could face legal consequences if procedural failures are found.
According to the referenced Polish Radio report, Poland's prime minister said the major Polish data breach was intended to extort a ransom. This adds motive information to the MyDr incident narrative.
Polish cybersecurity publication Zaufana Trzecia Strona reported that people claiming responsibility for the breach contacted the outlet and provided alleged evidence, including a screenshot containing information belonging to a prominent Polish politician. The reported samples have not been independently verified.
After identifying the incident, MyDr said it removed the cause and introduced additional security measures. The company also said its systems remained operational and safe for doctors and patients.
MyDr previously disclosed that parts of its systems were affected by what it described as external, intentional criminal activity. The company did not disclose the vulnerability or initial access method used in the attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcepolskieradio.pl
Open sourcepro.mydr.pl
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.