English Section
Follow us on Google

Follow us on Google to get our latest news at the top of your search results

Major Polish data breach aimed at extorting ransom, PM says

13.08.2026 19:30
A massive cyberattack on a Polish medical services company appears to have been motivated by an attempt to extort a ransom, Prime Minister Donald Tusk said on Thursday, as authorities probe a data breach that may have exposed the medical information of nearly 19 million people.
Audio
Polish Prime Minister Donald Tusk
Polish Prime Minister Donald TuskPhoto: PAP/Piotr Nowak

"The motivation appears to be purely criminal; much indicates that this was an attempt to extort a ransom from the company," Tusk told reporters.

He said the investigation was ongoing and that state security services were involved.

Tusk told a news conference in Warsaw that "no private company anywhere in the world can guarantee 100-percent protection" against cyberattacks.

"We are focusing on making sure there are no leaks, or as few leaks as possible, from our institutions," he said.

Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski confirmed on Wednesday that medical services company MyDr had been targeted in a cyberattack in which more than 2 terabytes of data was stolen, including information about medication and prescriptions affecting nearly 19 million people.

Deputy Prime Minister and Digital Affairs Minister Krzysztof Gawkowski confirmed onWednesday that medical services company MyDr had been targeted in a cyberattack in which more than 2 terabytes of data were stolen, including information about medications prescribed to millions of patients.

Gawkowski said on Thursday that the stolen data had not been publicly released, put up for sale or used as part of any extortion attempt.

"The situation is being monitored," Gawkowski said.

He again urged citizens to lock their PESEL personal identification numbers, a measure intended to help prevent their misuse.

Gawkowski said authorities were working to extract the compromised data from MyDr's systems and transfer it to government systems.

Citizens will soon be able to check whether their data were compromised on the government website bezpiecznedane.gov.pl, he said.

He also said security services were working to identify the group behind the attack.

There is no indication that the cyberattack originated abroad, Gawkowski said.

No negotiations with hackers

He told reporters that the government would not negotiate with those responsible.

"The ministry and state services do not negotiate with hackers," he said. "We hunt criminals down; we do not strike deals with them."

Asked whether those responsible for the breach had demanded a ransom, Gawkowski said the information was classified. 

The Warsaw District Prosecutor's Office said on Thursday that it was supervising an investigation by the Polish police's Central Bureau for Combating Cybercrime (CBZC).

Prosecutor Piotr Antoni Skiba said the investigation focused on unauthorised access to MyDr's computer system, followed by the possible disclosure of some of the stolen information to third parties.

The investigation also concerns the unauthorized processing of personal data, including health information, prosecutors said.

The offence carries a possible prison sentence of up to three years, Polish state news agency PAP reported.

The compromised information includes patients' names, PESEL numbers, telephone numbers, email addresses and health information, including notes from medical consultations and prescription records.

Prosecutors declined to provide further details, citing the interests of the ongoing investigation.

(gs)

Source: IAR/PAP

Click on the audio player above for a report by Piotr Urbaniak