Keep our news free from ads and paywalls by making a donation to support our work!

Notes from Poland is run by a small editorial team and is published by an independent, non-profit foundation that is funded through donations from our readers. We cannot do what we do without your support.

The personal data of almost 19 million people, including medical information, has been compromised in a major cyberattack on a company that provides services to thousands of medical facilities in Poland.

“We are dealing with one of the largest incidents in Poland’s history,” said digital affairs minister Krzysztof Gawkowski on Wednesday. He urged people to use government services to check whether their data is affected and to “lock” their national identity number to prevent potential fraud.

The attack targeted MyDr, a company that provides services used by many medical facilities in Poland. Its data includes patients’ personal information, as well as medical details such as diagnoses and prescriptions.

It was first reported on Monday by Zaufana Trzecia Strona, an IT security news service, which said that it had been contacted on Saturday by the alleged perpetrators, who claimed to have accessed the data of around 18.8 million people.

The hackers, who have not been identified, had also sent a screenshot from the compromised database showing the personal data of “one of the most important politicians in Poland”, added Zaufana Trzecia Strona.

Shortly afterwards, MyDr confirmed that it had “become the target of an external, deliberate criminal activity involving some of our data”. In an update on Wednesday, it said that, at the time of writing, there was no evidence that the data had been published anywhere.

Gawkowski addressed the issue at a press briefing on Wednesday. He noted that “there is no indication we are dealing with an external attack…from Russia or any other country”. Poland has recently regularly been targetted by Russian state-linked hackers.

It is “very likely” that cybercriminals are behind the attack on MrDr, said Gawkowski, who pledged that there would be an “uncompromising” response from the Polish security services.

The minister advised Poles to check in a secure government database whether their data had been leaked. He also advised citizens to use the state web portal, known as mObywatel, to “lock” their identity number, known as a PESEL, which prevents fraudsters from using it.

Around 12,000 medical facilities use MyDr’s services, the digital affairs ministry told the Polish Press Agency (PAP). The company claims that it processes three million medical consultations and 2.7 million prescriptions a month, reports the Gazeta Wyborcza daily.

Notes from Poland is run by a small editorial team and published by an independent, non-profit foundation that is funded through donations from our readers. We cannot do what we do without your support.

Pin It on Pinterest

Support us!