{"id":15533,"date":"2026-08-19T12:28:36","date_gmt":"2026-08-19T09:28:36","guid":{"rendered":"https:\/\/newsfire.gr\/en\/tusk-government-hid-data-breach-affecting-19-million-poles-for-two-years\/"},"modified":"2026-08-19T12:28:36","modified_gmt":"2026-08-19T09:28:36","slug":"tusk-government-hid-data-breach-affecting-19-million-poles-for-two-years","status":"publish","type":"post","link":"https:\/\/newsfire.gr\/en\/tusk-government-hid-data-breach-affecting-19-million-poles-for-two-years\/","title":{"rendered":"Tusk Government Hid Data Breach Affecting 19 Million Poles for Two Years"},"content":{"rendered":"<p>According to <em>Brussels Signal<\/em>, deputy digital affairs minister <strong>Micha\u0142 Gramatyka<\/strong> admitted he had no knowledge of a leak involving medical data that actually occurred as far back as two and a half years ago, despite the government initially claiming the breach was recent.<\/p>\n<p>Digital affairs minister <strong>Krzysztof Gawkowski<\/strong>, who also serves as deputy prime minister, publicly acknowledged on August 12 that data concerning 19 million Poles held by MyDr had been leaked. At that time, he maintained the breach had occurred within recent days, calling it an extraordinary incident affecting Poland&#8217;s information security sphere.<\/p>\n<p>However, the news website Niezale\u017cna reported on August 17 that a strikingly similar incident had already taken place two and a half years earlier, involving almost exactly the same number of data records. Between March 18 and 27, 2024, hackers obtained the data of 18,814,054 Polish citizens, including names, PESEL identification numbers, and information on health insurance coverage status.<\/p>\n<p>The matter first came to light on August 10 when Zaufana Trzecia Strona, an IT security news service, reported being contacted by alleged perpetrators who claimed access to approximately 18.8 million records. The hackers even provided a screenshot showing personal data of what they described as one of Poland&#8217;s most important politicians.<\/p>\n<p>Warsaw district prosecutors are now investigating unauthorized access to MyDr&#8217;s systems obtained no later than August 6. The breach targeted one of Poland&#8217;s largest electronic medical-record providers, with the stolen database exceeding 2 terabytes in size. Around 12,000 medical facilities rely on MyDr&#8217;s services, which processes 3 million medical consultations and 2.7 million prescriptions monthly.<\/p>\n<p>The compromised information included names, PESEL identification numbers, phone numbers, email addresses, and highly sensitive health information such as notes from medical appointments and prescription details, according to the Warsaw District Prosecutor&#8217;s Office.<\/p>\n<p>Most troubling is the revelation that the Regional Prosecutor&#8217;s Office in Pozna\u0144, western Poland, had already opened an investigation into the earlier 2024 incident on April 8, 2024, following notification from the president of the National Health Fund. Yet neither the Ministry of Digital Affairs nor the data protection authority UODO were informed about either the leak or the investigation.<\/p>\n<p>Pozna\u0144 prosecutors confirmed on August 18 that two individuals have been charged in connection with the 2024 breach. Their statement described how an intruder broke into a medical centre&#8217;s network, then implanted a script in MyDr that sent approximately 18 million automated queries to the NFZ&#8217;s patient-entitlement verification system, known as eWU\u015a.<\/p>\n<p>When confronted after the Niezale\u017cna article was published, Gramatyka confirmed his ignorance of the prior incident, telling journalists he had only learned about the matter at the same time they did. He expressed doubt that such a large batch of data was leaked in March 2024 and that these represented two separate incidents.<\/p>\n<p>However, a document from the prosecutor&#8217;s office reviewed by Niezale\u017cna contradicts that assessment, confirming that in 2024 the personal data of 18,814,054 individuals was unlawfully obtained, including names and PESEL numbers, thereby causing harm to the National Health Fund, Poland&#8217;s national health service contracting agency.<\/p>\n<p>The offence under investigation carries a possible prison sentence of up to two years under article 267 of the Polish penal code. Zaufana Trzecia Strona has maintained the two episodes are separate incidents despite the near-identical victim counts.<\/p>\n<p>The scandal represents a significant embarrassment for the Tusk government, which has positioned itself as competent and reform-minded since taking power. The failure to detect or be notified of such a massive breach for over two years raises fundamental questions about governmental oversight of critical national infrastructure and data security protocols.<\/p>\n<p style=\"text-align:right\"><em>With information from <a href=\"https:\/\/brusselssignal.eu\" target=\"_blank\" rel=\"noopener\">Brussels Signal<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Poland&#8217;s government was unaware for over two years that a data breach exposed personal and medical records of nearly 19 million citizens, raising cybersecurity concerns.<\/p>\n","protected":false},"author":39,"featured_media":15532,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[122],"tags":[3189,11993,1086,2265,11994,11995,937],"nfg_topic":[134],"class_list":["post-15533","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cybersecurity","tag-data-breach","tag-donald-tusk","tag-krzysztof-gawkowski","tag-medical-records","tag-mydr","tag-poland","nfg_topic-europe"],"_links":{"self":[{"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/posts\/15533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/comments?post=15533"}],"version-history":[{"count":0,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/posts\/15533\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/media\/15532"}],"wp:attachment":[{"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/media?parent=15533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/categories?post=15533"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/tags?post=15533"},{"taxonomy":"nfg_topic","embeddable":true,"href":"https:\/\/newsfire.gr\/en\/wp-json\/wp\/v2\/nfg_topic?post=15533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}