Wiadomości PRO
Latest

Leak of 19 million records: did the government fail and what must you do?

Administrator Redakcji 📅 Yesterday, 23:02 👁 1
As a result of an unprecedented cyberattack on a medical company, the data of 19 million Poles has been compromised. This incident is considered one of the largest in the history of Polish cybersecurity.
No time to read? Our AI narrator will read it to you. About 4 min.
At the end of the article: adapt this text to yourself (simpler, shorter, more detail) and ask a question about it — we answer only from this article.
Leak of 19 million records: did the government fail and what must you do?
fot. serwisy fotograficzne / archiwum Wiadomości PRO

The government maintains that the state has fulfilled its obligations, while experts recommend changing passwords immediately and monitoring accounts following the data leak of 19 million Poles. The authorities' decision to limit communication to assurances about pursuing the perpetrators stands in stark contrast to the concerns of citizens whose most sensitive medical information has fallen into the hands of criminals. The scale of the incident from August 12, 2026, necessitates taking protective measures before the stolen information is used for identity theft or financial fraud.

What you must do right now: a survival guide

Time is currently your most valuable resource, and passivity favors cybercriminals. Do not wait for official notifications from medical facilities or offices, which may arrive with a delay.

The first step is to change all access passwords. Focus primarily on electronic banking, email, and your trusted profile (profil zaufany). The password must be unique – do not use strings of characters that you use on other services. If you use the same password in multiple places, changing it on one service is only a half-measure.

Enable two-factor authentication (2FA) wherever the system allows it. This is a barrier that often prevents a break-in even if a third party knows your password. A code sent to a mobile device or generated by an app is currently the most effective way to secure an account.

Monitor your credit history and activity on your bank accounts. Any unusual transaction, even for a symbolic amount, should be a signal to contact your bank immediately. Download a report from the Credit Information Bureau (BIK) to check if any obligations have been taken out in your name recently.

Remain extremely vigilant against phishing attacks. Expect a wave of emails and SMS messages impersonating medical institutions or government offices. Criminals will try to extort further data by citing the incident or offering help in "verifying" your status in the database. Never click on suspicious links and do not provide login credentials on sites you were redirected to from a message.

Chronology: the course of the incident

| Date | Time | Event | Source |
| :--- | :--- | :--- | :--- |
| 12.08.2026 | 09:30 | First reports of an attack on a medical company | Rzeczpospolita |
| 12.08.2026 | 12:12 | Official confirmation of the leak by the government | PolsatNews.pl |
| 12.08.2026 | 12:13 | Confirmation of the attack scale for 19 million people | CyberDefence24 |
| 12.08.2026 | 12:49 | Classification of the incident as one of the largest | wnp.pl |
| 12.08.2026 | 15:03 | Announcement about the theft of sensitive data | Interia Wydarzenia |
| 12.08.2026 | 15:58 | Expert recommendations regarding data protection | Money.pl |
| 14.08.2026 | 08:57 | Analysis of threats stemming from digitalization | TVN24 |
| 14.08.2026 | 17:41 | Ministry declares tracking down the perpetrators | Wiadomości Onet |

Data analysis: why is a medical leak the most dangerous?

Most Poles have become accustomed to data leaks involving online stores or social media portals. Usually, these involve the need to change a password or replace a payment card. The incident from August 2026 is different. Medical data was stolen—information of a sensitive nature that cannot be changed.

Your medical history, test results, surgeries undergone, or information about medications taken are details that stay with you for the rest of your life. Unlike a payment card number, you cannot "replace" your medical records after they hit the black market. Once disclosed, the data becomes a permanent element of a citizen's digital profile, which can be used for blackmail, extortion attempts, or in recruitment processes where an employer illegally seeks information about a candidate's health status.

The scale of 19 million victims means that practically every second resident of Poland is exposed to the direct consequences of this attack. This is not an incident that can be limited to a specific region or age group. The very core of the healthcare system, which has rapidly accelerated its digitalization process in recent years, has been struck. In the rush to provide patients with easier access to e-prescriptions or e-referrals, it was often forgotten that every digital gateway is a potential entrance for cybercriminals.

Advertisement

Government defense and lack of accountability

State authorities, including representatives of ministries responsible for digitalization, have adopted a defensive strategy based on distancing themselves from the problem. The official government position, voiced since August 12, boils down to the thesis that the state has fully fulfilled its supervisory duties. In the government narrative, the culprit is a private entity—the medical company that managed the database.

From the perspective of the government administration, state systems are functioning flawlessly, and the break-in at a private facility is an "external incident." Such argumentation is highly problematic for citizens. Since the state promotes digitalization and encourages the use of e-health systems, citizens have the right to expect that the oversight of the security of this data goes beyond bureaucratic procedures.

The minister responsible for digitalization, speaking on August 14, assured that services are working intensively to track down the perpetrators. The declaration of "being on the trail" is intended to calm the mood, but in the face of the fact that the data has long since been stolen, it sounds like a technocratic dodge. Officials have not indicated which specific oversight mechanisms failed in the medical sector, nor how they intend to minimize the negative consequences for the affected patients. The lack of specific names of people responsible for oversight in the ministry or specific supervisory bodies that were supposed to conduct a security audit before the attack raises questions about the real effectiveness of state security measures.

Ministry building in Warsaw, site of the press conference after the leak.
Ministry building in Warsaw, site of the press conference after the leak.

Expert diagnosis: reality versus propaganda

Independent cybersecurity specialists do not share the optimism flowing from official government statements. In analyses appearing in media such as wnp.pl or CyberDefence24, this incident is described as one of the most serious in Poland's history. Experts point out that the state has the tools to enforce security, but in the case of the medical sector, there was clearly a lack of rigor.

The question arises: was it a system error or a human factor? Answers to this are still missing. It is only known that data of such a huge scale would not have leaked without a serious violation of procedures within the attacked company. The lack of transparency in the first hours after the attack only deepened the information chaos. Experts suggest that in the future, every entity processing sensitive medical data should be subject to periodic, rigorous penetration tests, for which the appropriate supervisory body would be directly responsible.

In the current situation, instead of counting on government explanations, specialists recommend a "zero trust" approach. This means not trusting any communications coming from unverified sources, even if they look like official letters from a clinic or hospital. Every email with an attachment regarding the data leak should be treated as a fraud attempt.

Advertisement

Digitalization that outpaced security

The development of digital technologies in Poland in recent years has been impressive, but it came at the cost of building an adequate security "shield." As the TVN24 station noted in its report from August 14, digitalization increases the threat of cyberattacks. This statement is obvious to IT professionals but still underestimated by political decision-makers.

Implementing systems that store information about 19 million people required infrastructure with the highest level of resistance to attacks. Meanwhile, Polish medical facilities, often underfunded, had to implement complex IT solutions without the support of adequate cybersecurity specialists. The result is a loophole that was mercilessly exploited.

What happened on August 12 is a brutal lesson for the entire state. Digitalization cannot be an end in itself if it is not accompanied by systemic guarantees of privacy protection. When the data of 19 million people becomes a commodity on the black market, one cannot speak of a success of digitalization. One can speak of a failure that will take years to repair.

Cybersecurity expert analyzing data on multiple monitors.
Cybersecurity expert analyzing data on multiple monitors.

Social consequences: is rebuilding trust possible?

Trust in digital services in Poland has been put to the ultimate test. Citizens who have been convinced to use e-services for years feel cheated. It is not just about the fact of the leak, but about the way the government communicated after the problem occurred. Assurances about "fulfilling duties" stand in opposition to the fact that half the country's population has lost control over their most intimate data.

The sense of threat that has accompanied Poles since August 12 is fully justified. Medical data, unlike shopping data, carries an emotional charge. The disclosure of diagnoses, treatments, or psychotherapy history is a violation of personal dignity that no apology from an official will fix.

Many citizens are asking themselves where their data is now and who possesses it. The lack of answers to this question from state bodies exacerbates fear. If the government does not present a concrete recovery plan that goes beyond prosecuting criminals, distrust of state digital systems will grow. This may lead to a retreat from e-services, which in the long run will set us back in administrative development.

Identity threats – how to defend yourself in the long term?

The leak of 19 million Poles' data is not just a current problem. It is a threat spread over years. Personal data, PESEL numbers, and medical history are a ready-made set for criminals involved in identity theft.

A person who has come into possession of such complete information can try to take out loans, open bank accounts, and even defraud social benefits or medication refunds. That is why it is so important to monitor the situation not just for the next week, but for the coming months and years.

An important element of protection is using credit alert services. Many banks offer notifications about every attempt to check creditworthiness at the BIK. If you receive an SMS about such an inquiry and you did not apply for a loan, it is a signal that someone is trying to use your data.

It is also worth considering reserving your PESEL number in the appropriate state register. This is a solution that makes it significantly harder for criminals to take out financial obligations using someone else's data. Although this mechanism is not 100% airtight, it constitutes a significant obstacle for fraudsters.

Concerned citizen checking notifications on a smartphone.
Concerned citizen checking notifications on a smartphone.

Legal liability: what about GDPR?

An incident on such a scale must be subjected to a thorough analysis in light of GDPR (General Data Protection Regulation) provisions. The medical company that lost the data faces huge financial penalties, but that is only one side of the coin.

It is important to determine whether the state—as the administrator of the e-health system—sufficiently supervised the process of securing data by private entities. If audits were superficial or not conducted at all, responsibility for the leak is blurred between the company and state bodies.

Poles have the right to compensation for the violation of personal data protection. In the case of medical data, which is particularly protected, these amounts can be significant. However, the path to obtaining redress is long and complicated, requiring proof of damage, which is often difficult in the case of a data leak. Nevertheless, mass lawsuits against entities that allowed such a gigantic leak may become the only effective tool forcing companies to invest in cybersecurity.

Are state systems really secure?

The government claims that the state has fulfilled its duties, but this declaration sounds increasingly empty in light of the facts. If the state promotes the centralization of data in digital systems, it must ensure security not only on its own servers but also throughout the entire supply chain of medical services.

The recent attack shows that the weakest link is external companies cooperating with the system. The state cannot limit itself to being a passive regulator. It must impose strict technical standards, the fulfillment of which will be a necessary condition for providing services within the public healthcare system.

Currently, it seems that the priority was the speed of implementing solutions, not their resistance to attacks. Now that the milk has been spilled, we must audit the entire digital infrastructure of the state. Every system in which the data of millions of Poles is processed should undergo an independent security audit.

The role of media in informing about threats

The media played a key role in highlighting the problem as early as August 12. Without the quick reaction of editorial offices such as "Rzeczpospolita" or CyberDefence24, many Poles could have learned about the threat much later, which would have drastically reduced their chances of an effective reaction.

On the other hand, the media must avoid building panic. Reliable information about what can be done is more important than repeating emotional comments. The role of investigative journalists in this matter is just beginning. It is from them that we will expect answers to the question of who specifically allowed the negligence and why the warning systems did not work faster.

Symbolic shot of binary code on a screen as a metaphor for a data leak.
Symbolic shot of binary code on a screen as a metaphor for a data leak.

What this means for you: final conclusions

The scale of the medical data leak of 19 million Poles is a turning point in the history of Polish cyberspace. For the citizen, it means the necessity of moving to a higher level of care for their security online. If you have treated cybersecurity as a problem for "IT specialists" until now, this incident should be a signal to change your attitude.

Companies offering professional support in identity protection and cybersecurity will benefit, while citizens have lost something that cannot be recovered—the sense of privacy of medical information. The catch is that criminals now have a database that will allow them to carry out very precise social engineering attacks. They will know what you are sick with, where you are being treated, and what your document numbers are. This makes each of us a target for potential fraud.

All that remains for us is vigilance and the consistent application of digital hygiene rules. The state, despite assurances, is unable to guarantee 100% protection of our data. In this situation, our individual responsibility becomes the main line of defense. There is no return to the times before digitalization, but we must learn to live in a world where our data is a commodity, and each of us must be our own security chief.

Questions and answers

Is my medical data safe?

Unfortunately, as a result of the attack on the medical company, the data of 19 million people has been compromised, which requires each of us to be particularly vigilant in monitoring our credit history and account activity.

What is the government doing about this?

The government officially declares that the state has performed its tasks and that services are on the trail of the cyberattack perpetrators, however, no concrete plans for systemic repair of data oversight have been presented yet.

What are the first steps to protect my account?

Experts recommend immediately changing passwords on medical and financial services, enabling two-factor authentication, and monitoring login history and bank transactions.

Can I get compensation for the leak?

GDPR provisions provide for the possibility of seeking redress, but the legal path requires proving the damage suffered, which is a difficult and time-consuming process in the case of a data leak.

Why is this more dangerous than a payment card number leak?

Medical data is immutable—you cannot "replace" your medical history or health status information with new ones, which means that once disclosed, the information can be used against the citizen for their entire life.

Will reserving my PESEL help?

Yes, it is one of the most effective methods of limiting the risk of financial obligations being taken out on stolen data, so it is worth checking this option in state registers.

Should I expect calls from fraudsters?

Yes, a wave of phishing is very likely—criminals will try to impersonate offices or medical facilities to extort additional information from you under the guise of "help" after the leak.

Is changing a password in one place enough?

No, if you use the same passwords on different services, you must change them everywhere, because hackers automatically check stolen access data on the most popular portals.

Who bears responsibility for this incident?

Responsibility is shared between the attacked medical company and the state bodies that oversaw data security in the public healthcare system.

How long should I monitor my accounts?

Due to the fact that medical data is permanently compromised, vigilance should become your new habit—monitoring your credit history and bank transactions should be done regularly for the next few years.

Sources

Article prepared by the Wiadomości PRO editorial team with the support of artificial intelligence. Facts come from the sources listed above.

This text adapts to you
Have a question about this text? Ask.
We look for the answer in this article first. If it is not there, we check press sources and link them. We do not invent.

Read more in Latest

Komentarze (0)

Strona jest bardziej interaktywna po zalogowaniu przez Google Twoje imię zostanie automatycznie wypełnione, a komentowanie jest szybsze i bezpieczniejsze.
Komentarz pojawi się po zatwierdzeniu przez redakcję.

Ładowanie komentarzy...

← Wróć na stronę główną
× This page adapts to you

Wiadomosci PRO is a portal built from widgets — rates, reminders, quiz, weather. You choose what you see.

See widgets →
Udostępnij
Link skopiowany