2026-08-13 · view entry permalink →
MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion — and because it is a processor, not a controller, the people affected cannot be told directly
MyDr serves thousands of Polish healthcare facilities and, on figures the company itself gives, processes three million appointments and 2.7 million prescriptions a month (Zaufana Trzecia Strona, 2026-08-10). It published an incident statement updated 2026-08-12 at 18:35 CET confirming an intrusion: "Na tym etapie trwającego dochodzenia potwierdzamy, że staliśmy się celem zewnętrznego, celowego działania o charakterze przestępczym, którym objęta była część danych" — at this stage of the ongoing investigation we confirm that we became the target of an external, deliberate act of a criminal nature, which covered part of the data (MyDr, 2026-08-12). The company states the affected data is most likely historical, from 2024 and earlier, and may not cover all MyDr clients or all their patients; that its systems are fully operational and safe to use; that its cybersecurity partners monitoring the dark web have found no evidence the data has been published or shared publicly; and that it cannot yet confirm the quantity and type of data disclosed until forensic analysis completes (MyDr, 2026-08-12).
The claims that prompted the statement are considerably larger. People presenting themselves as the perpetrators contacted Polish security journalist Adam Haertle before the disclosure and said they hold 18,814,422 unique PESEL national identity numbers and 2.5 TB of data (Zaufana Trzecia Strona, 2026-08-10). The outlet's verification is careful and worth reading as a method rather than a verdict: it was sent a database record for a senior Polish politician whose date of birth, identity number, name and one of two phone numbers it independently confirmed, along with the correct national health-fund region; it asked the claimants to look up the identity numbers of four industry volunteers and received records for two, which with the author's own record makes three matches out of five checked. The outlet states it caught the claimants in no inconsistency within what it could check, while being explicit that its checking ability is limited and that it has no way to verify either the 2.5 TB volume or the 18-million figure — though it observes that the figure is consistent with the potential reach of a system serving thousands of practices. It also records that Gawkowski, whom it names as premier, wrote publicly that much suggests an unauthorised person may have gained access to the data.
The access chain is a lead, not a finding. Per the claimants' own account, they first obtained remote code execution through an XXE-class flaw in the handling of PKCS#12 certificates — "Według tego, co usłyszeliśmy od sprawców, najpierw udało im się uzyskać zdalne wykonanie kodu przez podatność typu XXE przy obsłudze certyfikatów PKCS#12" — which yielded a GitHub API key, from there the platform's source code, and from there the AWS infrastructure. The outlet's next sentence is the one that governs how this should be read: "Nie byliśmy w stanie niezależnie zweryfikować tych informacji" — we were not able to independently verify this information (Zaufana Trzecia Strona, 2026-08-10). MyDr says it cannot share technical details while the investigation runs. No CVE exists and no vendor has confirmed a vulnerability class; treat the chain as an unverified attacker narrative that is nonetheless a reasonable thing to check for in your own certificate-parsing paths.
The extortion mechanics are documented more solidly, because the outlet handled the artefacts. The claimants sent the company's chief executive a message on 5 August linking to a PDF that was supposed to self-delete after download and did not; the file was password-protected, and the claimants noted the password was the executive's own PESEL number — which the outlet points out is a low-entropy value and therefore no obstacle. The document framed the approach as an offer to purchase the results of a security audit, and contained internal corporate correspondence including personnel information and a whistleblower report, alongside a fragment of the company's partner-doctor database. The claimants also showed a message sent to company employees from the company's own bulk-SMS account, and named Jira and a HubSpot CRM among systems they say they reached in full (Zaufana Trzecia Strona, 2026-08-10). On attribution the outlet is deliberately unhelpful in the right way: the claimants write in English, use a Russian-style emoticon convention, and produce English that reads as though deliberately rewritten to imitate a non-native speaker from elsewhere — which it reads as an attempt to lay false trails.
The structural finding, and the reason this matters beyond Poland. MyDr cannot tell affected people they are affected. "MyDr jest jedynie "podmiotem przetwarzającym" zgodnie z RODO, a administratorem danych są placówki ochrony zdrowia, których są tysiące" — MyDr is only a processor under GDPR, and the controllers are the healthcare facilities, of which there are thousands (Zaufana Trzecia Strona, 2026-08-10). The outlet's assessment is that individuals therefore have no way to check their own exposure and must wait for MyDr to determine scope, notify each facility, and for each facility to notify its own patients — a chain it expects to take many days. MyDr's own statement is consistent with this: it says it will contact affected clients proactively once it establishes which facilities and which data are involved, will support them in reporting to the data-protection authorities and in patient communication, and that no reports from facilities are required at present.
Na tym etapie trwającego dochodzenia potwierdzamy, że staliśmy się celem zewnętrznego, celowego działania o charakterze przestępczym, którym objęta była część danych.
Według tego, co usłyszeliśmy od sprawców, najpierw udało im się uzyskać zdalne wykonanie kodu przez podatność typu XXE przy obsłudze certyfikatów PKCS#12.
Nie byliśmy w stanie niezależnie zweryfikować tych informacji.
MyDr jest jedynie "podmiotem przetwarzającym" zgodnie z RODO, a administratorem danych są placówki ochrony zdrowia, których są tysiące.