, , ,

Massive data leak in Poland: 19 million people at risk. What should foreigners do?

A major cyberattack has occurred in Poland targeting the medical company MyDr’s systems. The data of approximately 19 million people may be at risk. Experts warn that the stolen information could be used for phishing, fraud, and other crimes. Residents of Poland are already being advised to take security measures.

Data leak in Poland: what happened

The large-scale cyberattack became known on August 12. The target of the attack was the company MyDr, which provides medical institutions with software for patient management and data storage.

According to Polish authorities, around 12 thousand medical facilities across the country are using the company’s solutions. After the attack was detected, the system was disconnected from the network to limit the further spread of the threat.

Particular concern is raised by the potential scale of the incident. According to preliminary data, the data of approximately 19 million people may be at risk.

At the same time, the investigation is ongoing, so it is currently impossible to definitively confirm which specific information has fallen into the hands of the perpetrators

What data could have been accessed by hackers

The speech may concern personal and medical data of patients. Among the potentially compromised information are, in particular, PESEL numbers, contact details, information about medical services, medications, and prescriptions.

However, the authorities emphasize an important point: the mere existence of a PESEL number in a potentially stolen database does not mean that the perpetrators also obtained the complete medical documentation of the person

That is why the final consequences of the attack will only be understood after the analysis of the hacked systems is completed

Why the leak of medical data is especially dangerous

Medical information is particularly valuable to criminals. If wrongdoers have access to details about doctor visits, prescriptions, or medications taken, they can use this information to create convincing fraudulent messages.

For example, a person may receive an SMS supposedly from a clinic with information about a prescription or the need to pay for a medical service. If the message contains real information, it is much harder for the victim to recognize the fraud.

Experts therefore expect a possible second wave of attacks — phishing SMS, emails, calls, and attempts to gain access to bank accounts or other services.

What to do after the MyDr data leak

Polish specialists advise not to wait until stolen data is used, but to strengthen protection in advance

1. Block the PESEL number

One of the main steps is to establish a PESEL block. This can be done through mObywatel or at a municipal office.

Tego typu blokada pomaga chronić przed próbami wykorzystania PESEL do ubiegania się o pożyczkę, kredyt lub inne operacje finansowe na nazwisko właściciela.

After a large-scale leak, it is especially important to pay attention to messages related to medicine

If an SMS or email offers:

  • pay for the prescription;
  • confirm the medical appointment;
  • pay extra for the medicine;
  • visit the clinic’s website;
  • provide additional personal data,

you shouldn’t open the link right away.

Lepiej samodzielnie znaleźć oficjalny numer instytucji medycznej i sprawdzić informacje bezpośrednio.

3. Monitor bank transactions

If personal data has indeed been compromised, it is advisable to closely monitor your bank account and notifications about financial transactions

Any unknown operation or attempt to arrange a financial product should be checked immediately

Can you check if your data has been leaked

Polskie władze pracują nad mechanizmem, który umożliwi obywatelom sprawdzenie, czy ich dane były wśród informacji dotkniętych atakiem.

While the investigation continues, the exact list of compromised data and the final number of affected individuals remain unknown

The main advice from specialists right now is to not panic, but to increase vigilance. Even if a person does not use MyDr services directly, their data may have been processed by one of the medical organizations using the company’s software.

Major data leak in Poland — main news

Data of approximately 19 million people may be at risk. The potential leak affects not only ordinary personal information but also data related to medical services.

While Polish authorities investigate the cyberattack, citizens are advised to block their PESEL, be cautious with SMS and letters from medical institutions, and closely monitor their financial transactions

It is especially important to remember: after the leak of real personal data, a fraudulent message can look very convincing


Read more