< Back to all clusters
[TECHNOLOGY] · Poland · 8 sources

started · updated

MyDr cyberattack potentially exposes 18.8 million PESEL numbers in Poland

A major cyberattack on MyDr, a leading provider of electronic medical documentation software in Poland, has potentially compromised the personal data of approximately 18.8 million people. The breach includes names, PESEL numbers, phone numbers, email addresses, and sensitive medical information such as doctor visit notes and prescriptions. The Ministry of Digital Affairs has confirmed the scale of the threat, which affects over 12,000 medical facilities.

Experts warn that while a PESEL number alone may not be sufficient to secure a loan, it can be used in sophisticated social engineering attacks, identity theft, or to facilitate fraudulent contracts. To mitigate risks, authorities and financial institutions like Credit Agricole recommend that citizens use the mObywatel app or visit local municipal offices to block their PESEL numbers. Since June 2024, banks, lenders, and notaries in Poland are legally required to verify the status of a blocked PESEL before finalizing certain transactions.

In addition to the MyDr breach, reports indicate a rise in various phishing scams targeting Polish citizens through fake messages regarding tax refunds or telecommunications overpayments. Recent studies also highlight a misconception regarding vulnerability; while many believe seniors are the primary targets, data shows that younger adults (ages 18-24) report encountering fraudulent attempts impersonating public institutions at a significantly higher rate.

Entities

Central Bureau for Combating Cybercrime · ChronPESEL.pl · Credit Agricole · Financial Ombudsman · Ministry of Digital Affairs · MyDr · National Debt Register · Poland · mObywatel