DistantNews
Support us
Poland faces massive cyberattacks; health data of 19 million exposed
๐Ÿ‡ต๐Ÿ‡ฑ Poland /Technology

Poland faces massive cyberattacks; health data of 19 million exposed

From Rzeczpospolita · () Polish

Translated from Polish, summarized and contextualized by DistantNews.

At a glance

News Sources not specified Under investigation
  • Poland is experiencing a significant number of cyberattacks, with the head of the UODO data protection authority calling it one of the most targeted countries globally.
  • A recent data breach at MyDr, a medical service provider, exposed sensitive health information of nearly 19 million people, prompting investigations by the company, cybersecurity services, and the prosecutor's office.
  • The UODO is conducting its own investigation into MyDr to determine if the incident could have been avoided and to assess the technical and organizational measures in place to protect data.

Poland is facing a severe wave of cyberattacks, with the head of the Personal Data Protection Office (UODO), Edyta Wara-Leszczyล„ska, stating the country is "one of the most attacked states in the world." This alarming assessment comes in the wake of a massive data breach at MyDr, a medical service provider, which compromised the sensitive health information of nearly 19 million individuals.

We are one of the most attacked states in the world.

โ€” Edyta Wara-Leszczyล„skaDescribing the scale of cyberattacks targeting Poland.

The incident is considered highly serious due to the sheer number of affected individuals and the nature of the data stolen โ€“ patient health records. Investigations are underway by MyDr itself, national cybersecurity services, and the prosecutor's office, which is working to identify the perpetrators. The UODO has also launched its own control proceedings to examine the breach.

This is of course a very serious incident both due to the number of people who may have been affected by this attack and, above all, due to the scope of the data, because it is patient health information.

โ€” Edyta Wara-Leszczyล„skaAssessing the severity of the MyDr data breach.

MyDr operates as a data processor, meaning various medical facilities, from large networks like Lux Med and Medicover to smaller clinics and individual practitioners, entrust their patient data to the company. While some larger medical providers have indicated that the breach may have only affected certain facilities and potentially excluded health data, MyDr stated that the stolen information pertains to data up to 2024, which slightly mitigates the immediate tension but does not diminish the gravity of the problem.

We will conduct an explanatory proceeding, thanks to which we will determine whether this incident could have been avoided.

โ€” Edyta Wara-Leszczyล„skaOutlining the UODO's investigation into the MyDr data breach.

The UODO's investigation will focus on whether the incident was preventable. Inspectors will scrutinize MyDr's technical and organizational safeguards, including regular testing of security measures against evolving threats and the proper implementation of risk assessments. Past UODO investigations have frequently revealed that data controllers or processors failed to conduct adequate risk analyses or deliberately ignored risks like ransomware attacks to save costs, often compounded by a failure to update systems and monitor for breaches. Wara-Leszczyล„ska noted that if such issues are found at MyDr, it would unfortunately not be a new problem, given Poland's current vulnerability to large-scale cyber threats.

Often in the course of our proceedings, we come to the conclusion that the administrator or processor did not conduct a risk analysis or did it incorrectly, which resulted in them securing personal data improperly.

โ€” Edyta Wara-Leszczyล„skaExplaining common failures found in data protection cases.
DistantNews Editorial

Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.