CampaignSMS

Cyberattack on a medical system. Patients receive SMS messages about their PESEL numbers and health data – istotne.pl

Disturbing SMS messages are reaching patients who use facilities whose data was processed in the MyDr system. Although the messages may look like an attempt to steal data, everything indicates that they are related to a real cyberattack and a breach of medical data security.
SMS messages informing patients about a data security breach in the MyDr system are reaching them. One such message, received by our Reader, begins with the words: “We hereby inform you that the system of our processing entity, i.e. MyDr Sp. z o.o., has fallen victim to a cyberattack.” The latter part contains a warning that the data breach in the RGMedica system may include, among other things, PESEL numbers and health data.
To a recipient, such an SMS may look like an attempted scam. In this case, however, the situation is different. The message corresponds to information published by medical facilities in connection with a real security incident involving MyDr. Patients of other facilities using this system are receiving similar communications.
The Warsaw Regional Prosecutor’s Office has also officially reported on the matter. Investigators confirmed that, no later than 6 August 2026, an unidentified person gained unauthorized access to all or part of the IT system administered by MyDr. According to the prosecutor’s office, patients’ personal data may have been obtained, including first names, surnames, PESEL numbers, telephone numbers, email addresses and health data, such as information from medical appointments or data concerning issued prescriptions. The investigation is being conducted by the Central Bureau for Combating Cybercrime.
It should be emphasized, however, that receiving such a message does not mean that someone has used a specific patient’s data. Current communications from medical facilities state that a breach of confidentiality is not equivalent to the data being read, used or made publicly available. MyDr and external experts are analyzing the incident and monitoring the situation.
The latest information also indicates that the incident primarily involved a limited scope of historical data, mainly from before 12 April 2024. In some cases, data contained in canceled referrals issued later may also have been affected.
Above all, do not reply to the SMS or provide any additional data, passwords or authorization codes through it. If the message contains a link, it is safer not to open it before verifying the information with your clinic or directly through MyDr’s official channels.
For people whose data may have been affected by the incident, it is particularly important to consider reserving the PESEL number. Medical facilities notifying patients about the incident identify this as one of the preventive measures that can be taken in connection with the risk of personal data misuse.
The message visible in the submitted photograph therefore does not appear to be a classic phishing SMS. Its content corresponds to genuine notices distributed in connection with the cyberattack on MyDr. Caution is still advised, especially when clicking any links contained in the message.
The most important news from Bolesławiec and the surrounding area. Local, concise, every day.

source

Leave a Reply

Your email address will not be published. Required fields are marked *