Society55

Poland's largest medical data leak in the country's history has occurred. Here's what leaked and how to protect yourself

The MyDr electronic healthcare system, used by about 12,000 medical facilities across Poland, has suffered a massive hacker attack. Data of almost 19 million people has been stolen. This includes Belarusians living in Poland who have a PESEL number and have sought local medical care. We explain what information is in the hands of the attackers and what you need to do right now to avoid becoming a victim of financial fraudsters.

Illustrative photo: Nasha Niva

What happened and whose data was stolen?

Over 2 terabytes of information were stolen from the MyDr system — records of about 19 million patients. Approximately 3 million doctor visits pass through the platform each month.

Poland's Minister of Digital Affairs, Krzysztof Gawkowski, confirmed the incident, noting that there are currently no indications that foreign intelligence services are behind the attack. The Central Bureau for Combating Cybercrime (CBZC) is already investigating.

There is no confirmation yet that the database has been put up for sale on the dark web. It is likely that hackers are preparing the data for sale to smaller groups specializing in social engineering.

What exactly fell into the hands of the hackers?

According to preliminary data, the leak includes basic identification data:

  • First and last names,
  • Dates of birth,
  • PESEL numbers,
  • Contact phone numbers,
  • In some cases — visit histories, diagnoses, and prescribed medications (data up to 2024).

It is not yet precisely known whether any other data leaked — for example, passport data, photos, or numbers of other documents.

How to check if you've been hacked?

Not yet. On August 12, Minister Krzysztof Gawkowski announced that it would be possible to check on the website bezpiecznedane.gov.pl whether your data is among those stolen from the MyDr database.

However, the Polish police later stated that they currently consider this impractical. MyDr also decided not to notify the clinics whose data leaked.

What are the main dangers?

A combination of name, PESEL number, phone, and medical history is not just a leak, but a ready-made kit for complete digital identity theft. Polish cybersecurity experts highlight four main threats:

  • Thieves may try to use your data to take out micro-loans (so-called chwilówki) and installments (in services like Klarna) in your name, or open shell bank accounts for money laundering.
  • Attackers may call posing as your clinic, name your real diagnoses or medications, and demand additional payments for medical services or repayment of an imaginary debt to the clinic. They may also send viruses disguised as important test results or blackmail you with sensitive diagnoses.
  • It might be possible to try to create a duplicate of your SIM card with the operator to bypass SMS confirmations in banks and other services, or create a new one in your name. Moreover, with your complete profile, hackers can convince support services to reset your social media and email passwords.
  • Medical data allows attackers to impersonate you in online consultation systems and illegally prescribe psychotropic drugs in your name for further sale on the black market.

How to protect yourself?

The main advice from the Ministry of Digital Affairs is to block your PESEL immediately. All banks, credit organizations, and telecom operators are obliged to check the register of blocked PESEL numbers before issuing a loan or signing a contract.

If your PESEL is blocked, and a fraudster manages to take out a loan in your name or otherwise use your PESEL, you will not bear any responsibility for it, and the bank will not be able to demand repayment of the money from you.

To do this, log in to mobywatel.gov.pl (or the official mObywatel mobile application), click on the "Usługi" ("Services") menu at the bottom, and select the "Zastrzeż PESEL" ("Protect PESEL") function. Your status should turn green (blocked). You can unblock it at any time with a single click (for example, 10 minutes before a real visit to the bank).

You can also do this through the gov.pl website via this link or at any gmina office, even if you do not live there.

CERT Polska and the Office for Personal Data Protection (UODO) strongly recommend performing a few more actions:

  • Do not trust phone calls. Fraudsters will use your medical data to gain trust. If you receive a call allegedly from a private clinic, the National Health Fund (NFZ), or a bank, find the official number of the institution online yourself and call them back to verify.
  • Do not give anyone your data. Neither a bank nor a clinic will ever ask you to dictate a BLIK code, an SMS authorization code, or install a third-party program on your phone.
  • Forward suspicious SMS messages. If you receive a suspicious message, forward it to the free number 8080 (the official CERT Polska number for phishing analysis) and then delete it.

Change identity documents if needed

After the leak, the Ministry of Digital Affairs advises carefully monitoring bank accounts and transaction history. If you detect suspicious activity or know that your document data has leaked, you should immediately invalidate your identity document (Dowód Osobisty/Kartę Pobytu). This can be done:

  • In the mObywatel app (via the "Załatw Sprawę" service, more details here),
  • On the state portal Gov.pl,
  • In person at any office.

Don't fall for fakes

Amidst the panic, new fraud schemes have started appearing on social media:

  1. "PESEL change form." Fraudsters are spreading PDF documents offering to change your compromised PESEL to a new one. This is a scam: according to Polish law, changing a PESEL due to a leak is not possible. By filling out such forms, you voluntarily give attackers your mother's maiden name and your passport data.
  2. Fake verification websites. The authorities promised to upload the leaked data to the state database bezpiecznedane.gov.pl so everyone could check themselves. Phishing clone sites are already appearing online. Never enter your PESEL number on unknown resources that offer "quick verification."

«Nasha Niva» — the bastion of Belarus

SUPPORT US

Comments5

  • Толік
    19.08.2026
    Хай пачытаюць мой аналіз калу, калі ім цікава. А званкоў іхніх я не баюся.
  • Чытач
    19.08.2026
    Толік, вы статью почитайте перед тем как писать ерунду. Слили большой массив данных, включая Pesel номера. Что потенциально позволит злоумышленникам использовать эти данные, например, чтобы оформить от вашего имени кредиты и тд.
  • Шапочку из фольги надень,
    20.08.2026
    Чытач, Царевич жабинский. Нужен ты кому со своей по 1000 на заводе.

Now reading

New details emerge about the brutal February attack on a family near Smolevichi

New details emerge about the brutal February attack on a family near Smolevichi

All news →
All news

Trains stopped and rescuers called to "Slutski Hascіnec" metro station

Residents of an agro-town near Gomel groan from the invasion of the "mad cucumber" 1

Abkhaz blogger advocating for reconciliation with Georgia found dead in Tbilisi 2

Lavrov stated that Russia wants to resolve the issue of the war in Ukraine "by 'guy's rules'" 11

Flour price increase expected in Belarus 4

In twenty US states, thousands of people poisoned by Mexican salad. Two dead.

Minsk residents lined up in a long queue for Uzbek melons PHOTOS 3

China "cleaned out" its top general. A major shootout preceded this. 1

"Kailash, I'm coming." What kind of Belarusian disappeared in a terrible mudslide in Nepal 17

больш чытаных навін
больш лайканых навін

New details emerge about the brutal February attack on a family near Smolevichi

New details emerge about the brutal February attack on a family near Smolevichi

Main
All news →

Заўвага:

 

 

 

 

Закрыць Паведаміць