ctipilot.ch

MyDr electronic health record platform breach (Poland, 2026)

incident · incident:mydr-poland-ehr-breach-2026

Intrusion into MyDr, one of Poland's largest electronic medical record platforms, serving thousands of healthcare facilities. The company confirmed on 12 August 2026 that it had been the target of a deliberate external criminal act affecting part of its data, likely historical data from 2024 and earlier, and that it could not yet state the quantity or type of data involved. People presenting as the perpetrators claim 18,814,422 unique PESEL national identity numbers and 2.5 TB of data, and describe an access chain — remote code execution via an XXE flaw in PKCS#12 certificate handling, then a GitHub API key, source code and AWS infrastructure — that the reporting outlet states it could not independently verify. Because MyDr is a GDPR processor and the controllers are thousands of individual clinics, affected individuals cannot be notified centrally (MyDr, 2026-08-12; Zaufana Trzecia Strona, 2026-08-10).

Aliases: MyDr PESEL breach, wyciek danych MyDr

Coverage timeline
1
first 2026-08-13 → last 2026-08-13
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
4
pinned v19.2 · see below

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-13/mydr-poland-ehr-criminal-intrusion-confirmed-processor-gap · ATT&CK page ↗

Story timeline

  1. 2026-08-13MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion — and because it is a processor, not a controller, the people affected cannot be told directly
    active-threatsA Polish health-records processor confirms an intrusion, and because it is not the data controller it cannot tell the affected people

Where this entity is cited

  • active-threats1

Source distribution

  • databreaches.net1 (33%)
  • pro.mydr.pl1 (33%)
  • zaufanatrzeciastrona.pl1 (33%)

explore in graph

Entries about MyDr electronic health record platform breach (Poland, 2026) (1)

2026-08-13 · view entry permalink →

HIGHNATOB2

MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion — and because it is a processor, not a controller, the people affected cannot be told directly

MyDr serves thousands of Polish healthcare facilities and, on figures the company itself gives, processes three million appointments and 2.7 million prescriptions a month (Zaufana Trzecia Strona, 2026-08-10). It published an incident statement updated 2026-08-12 at 18:35 CET confirming an intrusion: "Na tym etapie trwającego dochodzenia potwierdzamy, że staliśmy się celem zewnętrznego, celowego działania o charakterze przestępczym, którym objęta była część danych" — at this stage of the ongoing investigation we confirm that we became the target of an external, deliberate act of a criminal nature, which covered part of the data (MyDr, 2026-08-12). The company states the affected data is most likely historical, from 2024 and earlier, and may not cover all MyDr clients or all their patients; that its systems are fully operational and safe to use; that its cybersecurity partners monitoring the dark web have found no evidence the data has been published or shared publicly; and that it cannot yet confirm the quantity and type of data disclosed until forensic analysis completes (MyDr, 2026-08-12).

The claims that prompted the statement are considerably larger. People presenting themselves as the perpetrators contacted Polish security journalist Adam Haertle before the disclosure and said they hold 18,814,422 unique PESEL national identity numbers and 2.5 TB of data (Zaufana Trzecia Strona, 2026-08-10). The outlet's verification is careful and worth reading as a method rather than a verdict: it was sent a database record for a senior Polish politician whose date of birth, identity number, name and one of two phone numbers it independently confirmed, along with the correct national health-fund region; it asked the claimants to look up the identity numbers of four industry volunteers and received records for two, which with the author's own record makes three matches out of five checked. The outlet states it caught the claimants in no inconsistency within what it could check, while being explicit that its checking ability is limited and that it has no way to verify either the 2.5 TB volume or the 18-million figure — though it observes that the figure is consistent with the potential reach of a system serving thousands of practices. It also records that Gawkowski, whom it names as premier, wrote publicly that much suggests an unauthorised person may have gained access to the data.

The access chain is a lead, not a finding. Per the claimants' own account, they first obtained remote code execution through an XXE-class flaw in the handling of PKCS#12 certificates — "Według tego, co usłyszeliśmy od sprawców, najpierw udało im się uzyskać zdalne wykonanie kodu przez podatność typu XXE przy obsłudze certyfikatów PKCS#12" — which yielded a GitHub API key, from there the platform's source code, and from there the AWS infrastructure. The outlet's next sentence is the one that governs how this should be read: "Nie byliśmy w stanie niezależnie zweryfikować tych informacji" — we were not able to independently verify this information (Zaufana Trzecia Strona, 2026-08-10). MyDr says it cannot share technical details while the investigation runs. No CVE exists and no vendor has confirmed a vulnerability class; treat the chain as an unverified attacker narrative that is nonetheless a reasonable thing to check for in your own certificate-parsing paths.

The extortion mechanics are documented more solidly, because the outlet handled the artefacts. The claimants sent the company's chief executive a message on 5 August linking to a PDF that was supposed to self-delete after download and did not; the file was password-protected, and the claimants noted the password was the executive's own PESEL number — which the outlet points out is a low-entropy value and therefore no obstacle. The document framed the approach as an offer to purchase the results of a security audit, and contained internal corporate correspondence including personnel information and a whistleblower report, alongside a fragment of the company's partner-doctor database. The claimants also showed a message sent to company employees from the company's own bulk-SMS account, and named Jira and a HubSpot CRM among systems they say they reached in full (Zaufana Trzecia Strona, 2026-08-10). On attribution the outlet is deliberately unhelpful in the right way: the claimants write in English, use a Russian-style emoticon convention, and produce English that reads as though deliberately rewritten to imitate a non-native speaker from elsewhere — which it reads as an attempt to lay false trails.

The structural finding, and the reason this matters beyond Poland. MyDr cannot tell affected people they are affected. "MyDr jest jedynie "podmiotem przetwarzającym" zgodnie z RODO, a administratorem danych są placówki ochrony zdrowia, których są tysiące" — MyDr is only a processor under GDPR, and the controllers are the healthcare facilities, of which there are thousands (Zaufana Trzecia Strona, 2026-08-10). The outlet's assessment is that individuals therefore have no way to check their own exposure and must wait for MyDr to determine scope, notify each facility, and for each facility to notify its own patients — a chain it expects to take many days. MyDr's own statement is consistent with this: it says it will contact affected clients proactively once it establishes which facilities and which data are involved, will support them in reporting to the data-protection authorities and in patient communication, and that no reports from facilities are required at present.

Na tym etapie trwającego dochodzenia potwierdzamy, że staliśmy się celem zewnętrznego, celowego działania o charakterze przestępczym, którym objęta była część danych.

MyDr (company incident statement) 2026-08-12

Według tego, co usłyszeliśmy od sprawców, najpierw udało im się uzyskać zdalne wykonanie kodu przez podatność typu XXE przy obsłudze certyfikatów PKCS#12.

Nie byliśmy w stanie niezależnie zweryfikować tych informacji.

MyDr jest jedynie "podmiotem przetwarzającym" zgodnie z RODO, a administratorem danych są placówki ochrony zdrowia, których są tysiące.

Zaufana Trzecia Strona 2026-08-10
incident13 Aug 05:05Zmulti-sourceOpen finding ↗