European nation rocked by major hacker attack: “largest data leak in history”
Nearly half of the country’s population had their medical data stolen.

Image by Cybernews.
- Hackers breached MyDr, Poland's top medical platform, exposing health records of nearly 19 million citizens, nearly half the population.
- Attackers proved the MyDr breach by leaking a top Polish politician's PESEL number, phone numbers, and 25 prescriptions.
- Officials call it one of history's largest data leaks, involving over 2.5 terabytes of stolen Polish medical information.
- Deputy PM Krzysztof Gawkowski says the MyDr breach appears financially motivated, not politically driven, per Polish officials.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
MyDr, a major Polish electronic medical documentation provider, has been hit by a data breach that exposed the personal information of over 18 million Poles. Hackers reportedly proved the attack by sharing prescriptions of high-ranking politicians.
Hardly any personal data is more important than medical information. That’s why this week’s MyDr data breach, carried out by unknown attackers, is so devastating. Millions of Poles have had their sensitive data stolen.
MyDr is Poland’s primary healthcare platform for scheduling appointments, viewing medical records, and receiving digital prescriptions. The platform works with tens of thousands of clinics in the European country.
Reportedly, hackers accessed information of over 18 million Poles, roughly half of the country’s population. State officials already call it one of the worst cybersecurity incidents in the country’s history.
We are dealing with one of the largest data leaks in history,- Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski told Polish media.
“There has been an extraordinary data leak involving nearly 19 million Polish citizens who received medical assistance."
MyDr platform has also confirmed it suffered an attack. According to the company, information involved in the attack likely dates to 2024 and earlier, and doesn’t include all MyDr customers and patients.
“We are currently unable to confirm the amount and type of data that was exposed. We will do so once the forensic analysis is completed and this information is confirmed,” MyDr explained in a data breach notice.
However, MyDr processes extremely sensitive data, such as the Polish version of the Social Security number, PESEL, medical prescriptions, doctor appointments, personally identifiable information (PII), and other data that medical staff handle to provide services.
Exposed data of important politicians
Meanwhile, the attackers appear to have advertised the true extent of access they obtained to Polish media. According to Wyborza.pl, they reached out to another media outlet, claiming the MyDr data breach.
Apparently, attackers could not contact MyDr representatives and instead opted to go to the media. Cybercrooks then explained they have data on 18.8 million Poles, which adds up to over 2.5 terabytes of information.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
As proof, hackers presented journalists with personal details belonging to "one of the most important politicians in Poland," revealing the person’s PESEL number, two phone numbers, and a list of 25 prescriptions prescribed to the politician.
However, Minister of Digital Affairs Gawkowski said there is no indication that the attack was politically motivated, adding that officials can say “with a great degree of certainty” the perpetrators are financially motivated cybercriminals.
“Anyone behind this attack must be aware that the ruthlessness of the Polish services will be final,” Gawkowski said.
Medical data is among the most valuable
Losing medical records poses a significant risk to the individuals involved. Most obviously, attackers can attempt to use names, addresses, and other data points for identity theft by setting up fraudulent accounts.
However, the real danger here is medical identity theft and insurance fraud. In such cases, attackers can impersonate individuals to obtain prescription drugs. And if the stolen information includes patient histories, it could lead to cases of blackmail.
What makes matters worse is that medical and biometric data are non-recoverable, which means that, unlike passwords or credit cards, users cannot change their medical histories once they've been coåçmpromised.
Check if your data has been leaked
Healthcare data is among the most valuable prizes on the cybercriminal underground because it often enables cybercriminals to file fraudulent medical claims, resulting in the illicit purchase of prescription drugs.
The Cybernews research team believes that attackers can exploit the data in multiple ways. One of them could be blackmail of public personalities.
“For attackers, the most obvious way to misuse the data is identity theft using leaked IDs. They could also attempt to blackmail individual citizens by using details of their appointments and procedures that may have been carried out on them. Medical information on notable citizens such as politicians, influencers, and TV personalities could be used in political propaganda,” the team explained.