БЕЛ Ł РУС

Poland's largest medical data leak in the country's history has occurred. Here's what leaked and how to protect yourself

19.08.2026 / 12:45

Nashaniva.com

The MyDr electronic healthcare system, used by about 12,000 medical facilities across Poland, has suffered a massive hacker attack. Data of almost 19 million people has been stolen. This includes Belarusians living in Poland who have a PESEL number and have sought local medical care. We explain what information is in the hands of the attackers and what you need to do right now to avoid becoming a victim of financial fraudsters.

Illustrative photo: Nasha Niva

What happened and whose data was stolen?

Over 2 terabytes of information were stolen from the MyDr system — records of about 19 million patients. Approximately 3 million doctor visits pass through the platform each month.

Poland's Minister of Digital Affairs, Krzysztof Gawkowski, confirmed the incident, noting that there are currently no indications that foreign intelligence services are behind the attack. The Central Bureau for Combating Cybercrime (CBZC) is already investigating.

There is no confirmation yet that the database has been put up for sale on the dark web. It is likely that hackers are preparing the data for sale to smaller groups specializing in social engineering.

What exactly fell into the hands of the hackers?

According to preliminary data, the leak includes basic identification data:

It is not yet precisely known whether any other data leaked — for example, passport data, photos, or numbers of other documents.

How to check if you've been hacked?

Not yet. On August 12, Minister Krzysztof Gawkowski announced that it would be possible to check on the website bezpiecznedane.gov.pl whether your data is among those stolen from the MyDr database.

However, the Polish police later stated that they currently consider this impractical. MyDr also decided not to notify the clinics whose data leaked.

What are the main dangers?

A combination of name, PESEL number, phone, and medical history is not just a leak, but a ready-made kit for complete digital identity theft. Polish cybersecurity experts highlight four main threats:

How to protect yourself?

The main advice from the Ministry of Digital Affairs is to block your PESEL immediately. All banks, credit organizations, and telecom operators are obliged to check the register of blocked PESEL numbers before issuing a loan or signing a contract.

If your PESEL is blocked, and a fraudster manages to take out a loan in your name or otherwise use your PESEL, you will not bear any responsibility for it, and the bank will not be able to demand repayment of the money from you.

To do this, log in to mobywatel.gov.pl (or the official mObywatel mobile application), click on the "Usługi" ("Services") menu at the bottom, and select the "Zastrzeż PESEL" ("Protect PESEL") function. Your status should turn green (blocked). You can unblock it at any time with a single click (for example, 10 minutes before a real visit to the bank).

You can also do this through the gov.pl website via this link or at any gmina office, even if you do not live there.

CERT Polska and the Office for Personal Data Protection (UODO) strongly recommend performing a few more actions:

Change identity documents if needed

After the leak, the Ministry of Digital Affairs advises carefully monitoring bank accounts and transaction history. If you detect suspicious activity or know that your document data has leaked, you should immediately invalidate your identity document (Dowód Osobisty/Kartę Pobytu). This can be done:

Don't fall for fakes

Amidst the panic, new fraud schemes have started appearing on social media:

  1. "PESEL change form." Fraudsters are spreading PDF documents offering to change your compromised PESEL to a new one. This is a scam: according to Polish law, changing a PESEL due to a leak is not possible. By filling out such forms, you voluntarily give attackers your mother's maiden name and your passport data.
  2. Fake verification websites. The authorities promised to upload the leaked data to the state database bezpiecznedane.gov.pl so everyone could check themselves. Phishing clone sites are already appearing online. Never enter your PESEL number on unknown resources that offer "quick verification."

Read also:

Article comments