DistantNews
Support us
Data Leak Exposes 19 Million Poles; Government Website Fails
๐Ÿ‡ต๐Ÿ‡ฑ Poland /Technology

Data Leak Exposes 19 Million Poles; Government Website Fails

From Rzeczpospolita · () Polish

Translated from Polish, summarized and contextualized by DistantNews.

At a glance

News Named sources Ongoing story
  • A data leak potentially affecting nearly 19 million Polish citizens has been reported, with stolen data exceeding 2 terabytes.
  • The government has directed citizens to a website, Bezpieczne Dane (bezpiecznedane.gov.pl), to check if their data was compromised, but the site is currently inaccessible, likely due to high traffic.
  • Affected individuals are advised to reserve their PESEL numbers via the mObywatel app or at a local office, as stolen information may include medical records and prescriptions.

A massive data breach has potentially exposed the personal information of almost 19 million Poles, impacting over 2 terabytes of sensitive data. The cyberattack targeted MyDr, a medical support system.

We are dealing with an unprecedented and very large incident in terms of the security of the Polish information sphere.

โ€” Krzysztof GawkowskiDeputy Prime Minister Krzysztof Gawkowski describing the scale of the data breach.

Deputy Prime Minister Krzysztof Gawkowski stated that the affected systems are now secure and operating normally. However, the government's attempt to provide a resource for affected citizens has faltered. The website Bezpieczne Dane, intended to inform individuals about the compromised data, is currently unavailable. This inaccessibility is likely due to an overwhelming number of users attempting to access it simultaneously, creating further anxiety for those affected.

As citizens, they will be informed about the next steps, including the provision of information about the stolen data in the Bezpieczne Dane database.

โ€” Krzysztof GawkowskiDeputy Prime Minister Gawkowski outlining the government's plan to inform citizens.

Information potentially leaked includes PESEL numbers, prescription details, medical visit records, and health histories. Gawkowski advised citizens to reserve their PESEL numbers as a precautionary measure, which can be done through the mObywatel app or at a local office. The Office of the Personal Data Protection (UODO) has reminded administrators who used MyDr services of their obligation to notify affected individuals promptly, ideally within 72 hours, and to report the breach to the UODO president. Failure to do so requires an explanation for the delay.

According to GDPR, in the event of a personal data breach, the controller shall without undue delay โ€“ where feasible, not later than 72 hours after becoming aware of the breach โ€“ notify the supervisory authority.

โ€” Office of the Personal Data Protection (UODO)The UODO reminding data controllers of their reporting obligations under GDPR.
DistantNews Editorial

Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.