After Data Leak, Be Cautious for Months, Expert Advises
Translated from Polish, summarized and contextualized by DistantNews.
At a glance
- Following a cyberattack on the data company MyDr, a cybersecurity center convened to assess the impact.
- Individuals whose data may have been compromised are advised to carefully read any official notifications received.
- Experts recommend vigilance for months, including changing passwords and being wary of phishing attempts, especially given the sensitive nature of medical data.
In response to a cyberattack targeting the systems and data of the company MyDr, an urgent Joint Operational Center for Cybersecurity was convened to determine the incident's consequences. For individuals who learn their data might have been leaked but have not yet received direct notification, experts advise careful review of any official communications.
If we are indeed dealing with a personal data protection breach, the obligations fall primarily on the administrator, i.e., the entity that decides on the purposes and methods of processing โ who is responsible for them.
Marlena Sakowska-Baryลa, an expert, stated that if a personal data breach has occurred, the primary responsibility lies with the data administrator โ the entity determining the purposes and methods of data processing. This administrator should inform affected individuals about the incident and outline necessary precautions. Sakowska-Baryลa emphasized that with such a high-profile case, many people will seek guidance even before receiving individual notices or public announcements.
I would start by carefully reading such information if it reaches us.
Given the potential leak of medical data, which is highly sensitive, individuals are advised to take heightened precautions for an extended period, potentially months rather than days. This includes checking if their PESEL number (Poland's national identification number) has been flagged and exercising extreme caution. The full extent of what might happen with the compromised data and how it could be exploited remains unclear.
Check first whether we have blocked the PESEL and maintain increased caution in the near future, and by saying this, I mean months rather than a few days.
Sakowska-Baryลa also noted that while blocking the PESEL number is a step, individual capabilities are limited. If login credentials or passwords were leaked, they must be changed immediately, not just for one system but across all accounts, including social media and service providers. Increased vigilance is crucial for any anomalies, such as unexpected calls, messages, or phishing attempts. Individuals who possess specific personal information might appear credible, making it easier to legitimize contact and potentially deceive recipients. Therefore, prolonged skepticism towards anyone using personal details to solicit action is recommended.
If it turns out that logins or passwords have been leaked, necessarily, they should be changed.
Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.