Necessary Cookies

Required for the site to function. Cannot be disabled.

Analytics Cookies

Help us understand how visitors interact with our site (Google Analytics via GTM).

Marketing Cookies

Used to track visitors and deliver personalised advertisements.

We use cookies to enhance your browsing experience and analyse site traffic. By clicking Accept All, you consent to our use of cookies. Privacy Policy
NewsFire Global
Home News Europe World Christianity Culture Wars Opinion Video
Information
About Us Authors Advertising Terms & Conditions Privacy Policy Contact
R2B Media
R2B NEWSFIRE.GR PAPAFOTIS.GR THRACTION HELLENIC CONSERVATIVES RIGHT2THEBONE YT
News Europe

Tusk Government Hid Data Breach Affecting 19 Million Poles for Two Years

Poland's government was unaware for over two years that a data breach exposed personal and medical records of nearly 19 million citizens, raising cybersecurity concerns.

Dimitris Papafotis
Dimitris Papafotis Editor in Chief
AUGUST 19, 2026 AT 12:28 PM

According to Brussels Signal, deputy digital affairs minister Michał Gramatyka admitted he had no knowledge of a leak involving medical data that actually occurred as far back as two and a half years ago, despite the government initially claiming the breach was recent.

Digital affairs minister Krzysztof Gawkowski, who also serves as deputy prime minister, publicly acknowledged on August 12 that data concerning 19 million Poles held by MyDr had been leaked. At that time, he maintained the breach had occurred within recent days, calling it an extraordinary incident affecting Poland’s information security sphere.

However, the news website Niezależna reported on August 17 that a strikingly similar incident had already taken place two and a half years earlier, involving almost exactly the same number of data records. Between March 18 and 27, 2024, hackers obtained the data of 18,814,054 Polish citizens, including names, PESEL identification numbers, and information on health insurance coverage status.

The matter first came to light on August 10 when Zaufana Trzecia Strona, an IT security news service, reported being contacted by alleged perpetrators who claimed access to approximately 18.8 million records. The hackers even provided a screenshot showing personal data of what they described as one of Poland’s most important politicians.

Warsaw district prosecutors are now investigating unauthorized access to MyDr’s systems obtained no later than August 6. The breach targeted one of Poland’s largest electronic medical-record providers, with the stolen database exceeding 2 terabytes in size. Around 12,000 medical facilities rely on MyDr’s services, which processes 3 million medical consultations and 2.7 million prescriptions monthly.

The compromised information included names, PESEL identification numbers, phone numbers, email addresses, and highly sensitive health information such as notes from medical appointments and prescription details, according to the Warsaw District Prosecutor’s Office.

Most troubling is the revelation that the Regional Prosecutor’s Office in Poznań, western Poland, had already opened an investigation into the earlier 2024 incident on April 8, 2024, following notification from the president of the National Health Fund. Yet neither the Ministry of Digital Affairs nor the data protection authority UODO were informed about either the leak or the investigation.

Poznań prosecutors confirmed on August 18 that two individuals have been charged in connection with the 2024 breach. Their statement described how an intruder broke into a medical centre’s network, then implanted a script in MyDr that sent approximately 18 million automated queries to the NFZ’s patient-entitlement verification system, known as eWUŚ.

When confronted after the Niezależna article was published, Gramatyka confirmed his ignorance of the prior incident, telling journalists he had only learned about the matter at the same time they did. He expressed doubt that such a large batch of data was leaked in March 2024 and that these represented two separate incidents.

However, a document from the prosecutor’s office reviewed by Niezależna contradicts that assessment, confirming that in 2024 the personal data of 18,814,054 individuals was unlawfully obtained, including names and PESEL numbers, thereby causing harm to the National Health Fund, Poland’s national health service contracting agency.

The offence under investigation carries a possible prison sentence of up to two years under article 267 of the Polish penal code. Zaufana Trzecia Strona has maintained the two episodes are separate incidents despite the near-identical victim counts.

The scandal represents a significant embarrassment for the Tusk government, which has positioned itself as competent and reform-minded since taking power. The failure to detect or be notified of such a massive breach for over two years raises fundamental questions about governmental oversight of critical national infrastructure and data security protocols.

With information from Brussels Signal

Share:
Dimitris Papafotis
Dimitris Papafotis

Dimitris Papafotis is the editor-in-chief of NewsFire.GR. He was born and raised in Athens. He studied at the Journalism Workshop (1991-1993). He currently lives in Pyrgos, Ilia, where he has been active in radio and various newspapers, while also maintaining his personal blog, Papafotis.gr.

According to Brussels Signal, deputy digital affairs minister Michał Gramatyka admitted he had no knowledge of a leak involving medical data that actually occurred as far back as two and a half years ago, despite the government initially claiming the breach was recent.

Digital affairs minister Krzysztof Gawkowski, who also serves as deputy prime minister, publicly acknowledged on August 12 that data concerning 19 million Poles held by MyDr had been leaked. At that time, he maintained the breach had occurred within recent days, calling it an extraordinary incident affecting Poland’s information security sphere.

However, the news website Niezależna reported on August 17 that a strikingly similar incident had already taken place two and a half years earlier, involving almost exactly the same number of data records. Between March 18 and 27, 2024, hackers obtained the data of 18,814,054 Polish citizens, including names, PESEL identification numbers, and information on health insurance coverage status.

The matter first came to light on August 10 when Zaufana Trzecia Strona, an IT security news service, reported being contacted by alleged perpetrators who claimed access to approximately 18.8 million records. The hackers even provided a screenshot showing personal data of what they described as one of Poland’s most important politicians.

Warsaw district prosecutors are now investigating unauthorized access to MyDr’s systems obtained no later than August 6. The breach targeted one of Poland’s largest electronic medical-record providers, with the stolen database exceeding 2 terabytes in size. Around 12,000 medical facilities rely on MyDr’s services, which processes 3 million medical consultations and 2.7 million prescriptions monthly.

The compromised information included names, PESEL identification numbers, phone numbers, email addresses, and highly sensitive health information such as notes from medical appointments and prescription details, according to the Warsaw District Prosecutor’s Office.

Most troubling is the revelation that the Regional Prosecutor’s Office in Poznań, western Poland, had already opened an investigation into the earlier 2024 incident on April 8, 2024, following notification from the president of the National Health Fund. Yet neither the Ministry of Digital Affairs nor the data protection authority UODO were informed about either the leak or the investigation.

Poznań prosecutors confirmed on August 18 that two individuals have been charged in connection with the 2024 breach. Their statement described how an intruder broke into a medical centre’s network, then implanted a script in MyDr that sent approximately 18 million automated queries to the NFZ’s patient-entitlement verification system, known as eWUŚ.

When confronted after the Niezależna article was published, Gramatyka confirmed his ignorance of the prior incident, telling journalists he had only learned about the matter at the same time they did. He expressed doubt that such a large batch of data was leaked in March 2024 and that these represented two separate incidents.

However, a document from the prosecutor’s office reviewed by Niezależna contradicts that assessment, confirming that in 2024 the personal data of 18,814,054 individuals was unlawfully obtained, including names and PESEL numbers, thereby causing harm to the National Health Fund, Poland’s national health service contracting agency.

The offence under investigation carries a possible prison sentence of up to two years under article 267 of the Polish penal code. Zaufana Trzecia Strona has maintained the two episodes are separate incidents despite the near-identical victim counts.

The scandal represents a significant embarrassment for the Tusk government, which has positioned itself as competent and reform-minded since taking power. The failure to detect or be notified of such a massive breach for over two years raises fundamental questions about governmental oversight of critical national infrastructure and data security protocols.

With information from Brussels Signal