ctipilot.ch
← Back to the live brief
HIGHNATOB2incident

MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion — and because it is a processor, not a controller, the people affected cannot be told directly

discovered 2026-08-13 05:05 UTCrun 2026-08-13T0412Z-intel3 sourcesmulti-source

MyDr serves thousands of Polish healthcare facilities and, on figures the company itself gives, processes three million appointments and 2.7 million prescriptions a month (Zaufana Trzecia Strona, 2026-08-10). It published an incident statement updated 2026-08-12 at 18:35 CET confirming an intrusion: "Na tym etapie trwającego dochodzenia potwierdzamy, że staliśmy się celem zewnętrznego, celowego działania o charakterze przestępczym, którym objęta była część danych" — at this stage of the ongoing investigation we confirm that we became the target of an external, deliberate act of a criminal nature, which covered part of the data (MyDr, 2026-08-12). The company states the affected data is most likely historical, from 2024 and earlier, and may not cover all MyDr clients or all their patients; that its systems are fully operational and safe to use; that its cybersecurity partners monitoring the dark web have found no evidence the data has been published or shared publicly; and that it cannot yet confirm the quantity and type of data disclosed until forensic analysis completes (MyDr, 2026-08-12).

The claims that prompted the statement are considerably larger. People presenting themselves as the perpetrators contacted Polish security journalist Adam Haertle before the disclosure and said they hold 18,814,422 unique PESEL national identity numbers and 2.5 TB of data (Zaufana Trzecia Strona, 2026-08-10). The outlet's verification is careful and worth reading as a method rather than a verdict: it was sent a database record for a senior Polish politician whose date of birth, identity number, name and one of two phone numbers it independently confirmed, along with the correct national health-fund region; it asked the claimants to look up the identity numbers of four industry volunteers and received records for two, which with the author's own record makes three matches out of five checked. The outlet states it caught the claimants in no inconsistency within what it could check, while being explicit that its checking ability is limited and that it has no way to verify either the 2.5 TB volume or the 18-million figure — though it observes that the figure is consistent with the potential reach of a system serving thousands of practices. It also records that Gawkowski, whom it names as premier, wrote publicly that much suggests an unauthorised person may have gained access to the data.

The access chain is a lead, not a finding. Per the claimants' own account, they first obtained remote code execution through an XXE-class flaw in the handling of PKCS#12 certificates — "Według tego, co usłyszeliśmy od sprawców, najpierw udało im się uzyskać zdalne wykonanie kodu przez podatność typu XXE przy obsłudze certyfikatów PKCS#12" — which yielded a GitHub API key, from there the platform's source code, and from there the AWS infrastructure. The outlet's next sentence is the one that governs how this should be read: "Nie byliśmy w stanie niezależnie zweryfikować tych informacji" — we were not able to independently verify this information (Zaufana Trzecia Strona, 2026-08-10). MyDr says it cannot share technical details while the investigation runs. No CVE exists and no vendor has confirmed a vulnerability class; treat the chain as an unverified attacker narrative that is nonetheless a reasonable thing to check for in your own certificate-parsing paths.

The extortion mechanics are documented more solidly, because the outlet handled the artefacts. The claimants sent the company's chief executive a message on 5 August linking to a PDF that was supposed to self-delete after download and did not; the file was password-protected, and the claimants noted the password was the executive's own PESEL number — which the outlet points out is a low-entropy value and therefore no obstacle. The document framed the approach as an offer to purchase the results of a security audit, and contained internal corporate correspondence including personnel information and a whistleblower report, alongside a fragment of the company's partner-doctor database. The claimants also showed a message sent to company employees from the company's own bulk-SMS account, and named Jira and a HubSpot CRM among systems they say they reached in full (Zaufana Trzecia Strona, 2026-08-10). On attribution the outlet is deliberately unhelpful in the right way: the claimants write in English, use a Russian-style emoticon convention, and produce English that reads as though deliberately rewritten to imitate a non-native speaker from elsewhere — which it reads as an attempt to lay false trails.

The structural finding, and the reason this matters beyond Poland. MyDr cannot tell affected people they are affected. "MyDr jest jedynie "podmiotem przetwarzającym" zgodnie z RODO, a administratorem danych są placówki ochrony zdrowia, których są tysiące" — MyDr is only a processor under GDPR, and the controllers are the healthcare facilities, of which there are thousands (Zaufana Trzecia Strona, 2026-08-10). The outlet's assessment is that individuals therefore have no way to check their own exposure and must wait for MyDr to determine scope, notify each facility, and for each facility to notify its own patients — a chain it expects to take many days. MyDr's own statement is consistent with this: it says it will contact affected clients proactively once it establishes which facilities and which data are involved, will support them in reporting to the data-protection authorities and in patient communication, and that no reports from facilities are required at present.

Na tym etapie trwającego dochodzenia potwierdzamy, że staliśmy się celem zewnętrznego, celowego działania o charakterze przestępczym, którym objęta była część danych.

MyDr (company incident statement) 2026-08-12

Według tego, co usłyszeliśmy od sprawców, najpierw udało im się uzyskać zdalne wykonanie kodu przez podatność typu XXE przy obsłudze certyfikatów PKCS#12.

Nie byliśmy w stanie niezależnie zweryfikować tych informacji.

MyDr jest jedynie "podmiotem przetwarzającym" zgodnie z RODO, a administratorem danych są placówki ochrony zdrowia, których są tysiące.

Zaufana Trzecia Strona 2026-08-10

ATT&CK mapping

4 techniques mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1078.004Valid Accounts: Cloud Accounts

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

overlap matrix · ATT&CK page ↗

T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1078.004Valid Accounts: Cloud Accounts

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1078.004Valid Accounts: Cloud Accounts

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

overlap matrix · ATT&CK page ↗

Stealth TA0005
T1078.004Valid Accounts: Cloud Accounts

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

overlap matrix · ATT&CK page ↗

Collection TA0009
T1213Data from Information Repositories

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.