ctipilot.ch
← Back to the live brief
NOTABLEupdateNATOB1incident

UPDATE — Poland's government puts the MyDr breach at nearly 19 million people and over 2 TB, and the regulator confirms the notification duty sits with the ~12,000 clinics, not the platform

discovered 2026-08-15 05:02 UTCrun 2026-08-15T0412Z-intel3 sourcesmulti-source

UPDATE · originally covered MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion — and because it is a processor, not a controller, the people affected cannot be told directly (2026-08-13)

the earlier entry recorded MyDr's own confirmation of a deliberate external criminal act, its statement that it could not yet say what was taken, and the structural observation — made at the time by the reporting outlet rather than by any authority — that because MyDr is a processor and the controllers are thousands of individual healthcare facilities, affected people could not be notified centrally. Both halves have now been settled by the Polish state.

At a press briefing following a meeting of the Joint Cybersecurity Operations Centre, Deputy Prime Minister and digital affairs minister Krzysztof Gawkowski said the leak may cover nearly 19 million people and that the stolen database exceeds 2 TB (Gazeta Prawna, 2026-08-13), and characterised it as "one of the largest incidents in Poland's history" (Notes from Poland, 2026-08-13). That replaces MyDr's hedged position with a government-stated figure. Gawkowski also said there is no indication of an attack from Russia or another state and that cybercriminals are "very likely" responsible — a notable framing for a country whose public sector is regularly targeted by state-linked actors, and one that shapes what kind of follow-on activity defenders should expect. Around 12,000 medical facilities use MyDr's services, per the digital affairs ministry (Notes from Poland, 2026-08-13). MyDr said in a Wednesday update that at the time of writing there was no evidence the data had been published anywhere.

The regulator has now put the notification structure in writing. Poland's data protection authority UODO stated that the obligation to notify people affected by the leak rests with the controllers that used MyDr's services, and reminded controllers that under GDPR a breach must be reported to the supervisory authority without undue delay and where feasible no later than 72 hours after becoming aware of it, with a reasoned explanation attached to any later report (Gazeta Prawna, 2026-08-13). UODO's advice to individuals is to lock their PESEL national identity number and to treat incoming SMS and email with more care to avoid phishing aimed at extracting further data or access to banking. Gawkowski separately urged people to use state services to check exposure and to lock their PESEL through the mObywatel portal (Notes from Poland, 2026-08-13).

“We are dealing with one of the largest incidents in Poland’s history,” said digital affairs minister Krzysztof Gawkowski on Wednesday.

Notes from Poland 2026-08-13

„Powiadomienia osób, dotkniętych wyciekiem danych, spoczywa na administratorach, którzy korzystali z usług spółki MyDr” - zwrócił uwagę Urząd.

Gazeta Prawna 2026-08-13

ATT&CK mapping

1 technique mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

Stealth TA0005
T1078Valid Accounts

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.