Wiadomości PRO
Poland

Leak of 19 million Poles' data: How to check if you are at risk?

Administrator Redakcji 📅 Today, 11:53 👁 1
An unprecedented personal data leak has occurred in Poland, affecting nearly 19 million citizens and thousands of institutions across the country. Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski is monitoring the situation in real-time, warning of the attack's consequences and providing guidance on how to verify your security.
No time to read? Our AI narrator will read it to you. About 4 min.
At the end of the article: adapt this text to yourself (simpler, shorter, more detail) and ask a question about it — we answer only from this article.
Wyciek 19 mln danych Polaków: Jak sprawdzić, czy jesteś zagrożony?
fot. Wisam Alazawi / Pexels

The data leak of nearly 19 million Poles includes PESEL numbers, ID card series and numbers, and detailed medical data. To check if you are at risk, you should use the special government website launched by the Ministry of Digital Affairs under the supervision of Deputy Prime Minister Krzysztof Gawkowski. This tool allows you to verify whether a specific person's information was included in the databases taken over by unauthorized entities.

Characteristics of the stolen information

Sets of information allowing for the full identification of citizens have fallen into the hands of third parties. The databases contain PESEL numbers, ID card series and numbers, and detailed medical data. These are data packages that, on the black market, serve as tools for identity theft. Possessing such a set, an attacker can impersonate a person in dealings with a financial institution, take out loans, or attempt to gain access to services requiring a high level of authentication. Deputy Prime Minister Krzysztof Gawkowski reported on August 12, 2026, on the ministry's actions taken to monitor the situation. According to official announcements, the data has not yet been massively published in open sources, which, however, does not change the fact that it is outside the owners' control.

For a person whose data has been leaked, the difference between the database being sold on a closed forum and its public release is technical. The risk of social engineering attacks has increased. Fraudsters possessing authentic data, such as a PESEL number or ID series, can make any attempt to extort information by phone appear credible. Posing as a bank employee or official becomes much more effective when the caller recites the victim's data. The aforementioned website bezpiecznedane.gov.pl is currently the only authorized government tool for checking your status in the database of people affected by the breach. Using other, unofficial websites appearing online is risky, as they may be used to further collect personal data from concerned citizens.

Security procedures and identity protection

In the face of such an extensive breach, a passive attitude increases the likelihood of financial damage. The first step must be verification on the official government portal. If the system shows your data is in the database, you must assume it has become a tool in the hands of third parties. A key action in 2026 is to reserve your PESEL number. You should go to the mObywatel application, select the "Reserve PESEL" function, and confirm the operation. This reservation means that financial institutions are required to check the status of the PESEL number before granting a loan or credit. If the PESEL is reserved, the credit procedure should be halted. This is a mechanism that significantly limits the possibility of incurring liabilities on stolen data.

In addition to reserving your PESEL, you should use services that monitor credit activity. The BIK (Credit Information Bureau) Alert is an early warning system that sends an SMS or email notification when someone applies for a loan in your name. Similar services are offered by other credit bureaus. Activating these alerts is a preventive measure. The next stage is changing passwords in banking services and email accounts. Use unique character strings for each portal. Where possible, enforce two-factor authentication (2FA). Give up SMS codes in favor of authentication apps such as Google Authenticator, Microsoft Authenticator, or hardware keys like YubiKey. These are much harder to take over than codes sent via mobile networks, which can be intercepted through SIM-swap attacks.

You should remain vigilant regarding messages received on your phone and email. Phishing attacks become precise after a leak. If you receive a call from someone claiming to be a bank employee who knows your PESEL or ID number, hang up. A bank employee will not ask for full sensitive data or passwords. If in doubt, hang up and dial the bank's hotline number yourself, using the institution's official website. Do not call back the number that appeared on the screen, as fraudsters use spoofing techniques, impersonating hotline numbers. Every unexpected request for data confirmation must be treated as an attempted fraud. Leaked databases can be used by criminals for many months.

Editorial context: challenges for the system

This leak is a test of the capacity of state personal data protection systems. Companies offering commercial identity monitoring services will see an increase in interest, but the social costs of the incident will be spread over time. The problem remains the lack of systemic protection against the consequences of PESEL number theft, which in the Polish legal system is a universal number used in offices, medical facilities, and banks. By providing the bezpiecznedane.gov.pl website, the state provides a diagnostic tool, but it does not constitute a protective shield against the data theft itself. Citizens must manage risk on their own, which requires knowledge of procedures such as reserving a PESEL or monitoring credit history.

The lack of clear procedures regarding the mass replacement of identity documents after such an incident is a gap that the state will have to define in the coming months. Currently, possessing a stolen ID card number allows criminals to attempt extortion, even if the PESEL number has been reserved. The PESEL reservation mechanism is a novelty that has not yet been fully integrated with all verification processes in the private sector. Institutions have time to adjust their systems, which means that in the transition period, the effectiveness of protection may be limited.

Advertisement

Questions and answers

Where can I safely check if my data has been leaked?

The only authorized source for verification is the government portal bezpiecznedane.gov.pl. The Ministry of Digital Affairs warns against using private websites offering similar services, as they may be used to further acquire personal data from users.

Is my money in the bank safe?

Funds in accounts do not disappear automatically as a result of the data leak itself. The risk arises when criminals use the stolen data to extort a loan or gain unauthorized access to electronic banking. It is essential to enable two-factor authentication and constantly monitor the account transaction history.

What exactly does it mean that "special data" was leaked?

This term refers to information of a sensitive nature. In this case, it includes the PESEL number, ID card series and number, and medical data. This scope of information enables criminals to effectively impersonate the victim in almost every public and commercial institution.

Am I safe after checking on the government website?

Checking your status is just the beginning. Even if your data has been stolen, an appropriate reaction – reserving your PESEL in mObywatel, activating BIK alerts, and remaining vigilant – drastically reduces the criminals' chances of success. Cybercriminals count on human error, which is why digital hygiene and a lack of trust in unexpected communications are most important.

How long can this data be dangerous?

Personal data, such as a PESEL number or ID series, is permanent data. The risk of its use does not expire after a few days or weeks from the incident. You should adopt a principle of limited trust in all incoming communication from the outside for the next few years. Criminals often wait for the right moment to use a database when the victim has lowered their guard.

Why is reserving a PESEL so important?

Reserving a PESEL in the state system blocks the possibility of unauthorized persons incurring financial liabilities. It is an effective barrier because banks and lending institutions are required to check the status in the reservation register before signing a contract. It is currently the most effective tool for protection against financial identity theft available to every citizen who has a Trusted Profile or the mObywatel application.

Can medical data be used for blackmail?

Yes, medical data is considered special category data. Its disclosure or possession by criminals can lead to attempts at blackmail or social engineering based on knowledge of the victim's medical history, which increases the credibility of fraudsters in the eyes of the attacked person. For this reason, after a leak, you should particularly protect your data in medical facilities and not share your PESEL number in unverified places.

Sources

This text adapts to you
Have a question about this text? Ask.
We look for the answer in this article first. If it is not there, we check press sources and link them. We do not invent.

Read more in Poland

Komentarze (0)

Strona jest bardziej interaktywna po zalogowaniu przez Google Twoje imię zostanie automatycznie wypełnione, a komentowanie jest szybsze i bezpieczniejsze.
Komentarz pojawi się po zatwierdzeniu przez redakcję.

Ładowanie komentarzy...

← Wróć na stronę główną
× This page adapts to you

Wiadomosci PRO is a portal built from widgets — rates, reminders, quiz, weather. You choose what you see.

See widgets →
Udostępnij
Link skopiowany