MyDr Breach: Five Leaks, One Missing Disclosure Channel

Poland's MyDr leak, Change Healthcare, Salesloft Drift, Free Mobile and Tea share one trait: nobody outside had a supported way to report a flaw.

Ernest Bursa

Ernest Bursa

Founder · · 18 min read
Security lead in his fifties briefing three colleagues at a marker-covered glass wall in a Dogpatch warehouse loft at dusk, a closed laptop on the table

On 12 August 2026, MyDr sp. z o.o., a Polish vendor of electronic medical records software, confirmed on its own incident page that it “became the target of external, deliberate criminal action” affecting “part of the data.” The attackers separately told the Polish security site Zaufana Trzecia Strona that they hold 18,814,422 unique PESEL numbers. MyDr confirms neither that figure nor any other. What MyDr shares with four other major breaches on three continents is narrower and more fixable than any of the root causes: when someone outside the company wanted to report something, there was no supported way to do it.

A vulnerability disclosure program would not have stopped any of these five breaches. This is an argument about who finds out first, and how long it takes.

What happened at MyDr, and the three numbers that do not match

MyDr builds records and practice-management software for Polish clinics. The Docplanner (ZnanyLekarz) group announced its acquisition on 9 January 2023. Three numbers are now in circulation, and they do not agree.

  • Claimed by the attackers: 18,814,422 unique PESEL numbers and roughly 2.5 TB. Zaufana Trzecia Strona states it could verify neither.
  • Stated by the government: Deputy Prime Minister Krzysztof Gawkowski said on 12 August that nearly 19 million records were stolen, “which the company itself confirms” (Bankier, 2026).
  • Confirmed by MyDr: nothing. Its page, updated at 18:35 CET the same day, says the company cannot confirm the quantity or type of data disclosed, and describes the affected data as “most likely historical, from 2024 and earlier years.”

The government statement and MyDr’s page are primary sources published hours apart, and they contradict each other on the central fact. No confirmed record count exists today. Zaufana Trzecia Strona did verify part of the attackers’ sample, including a senior politician’s record and three hits in a five-PESEL test. That corroborates one thing: the attackers hold real MyDr-shaped data. It does not corroborate 18.8 million.

The root cause is attacker-claimed and unverified: an XXE flaw in certificate handling leading to code execution, a stolen GitHub API key, then AWS. MyDr has published no technical detail, and attribution is deliberately muddied, so no group or country should be named. Detection dates are unknown; the company says it cannot give them while the investigation runs. No dwell time should be inferred.

The order of events is the point. On 5 August the attackers showed journalists a screenshot of a message they said they had sent the CEO of the platform’s owner: a link to a password-protected PDF whose password was the CEO’s own PESEL. On 8 August they contacted the press. MyDr’s first statement came on 10 August, the same day those journalists published.

Polish patients still cannot check whether they are affected. MyDr is a GDPR processor, so UODO’s 12 August communiqué places the duty to notify individuals on the controllers, meaning the thousands of clinics that used the software, and the national leak-check portal states MyDr’s data has not been loaded into it.

As for reporting a bug: probed on 12 August 2026, mydr.pl/.well-known/security.txt redirects to a catch-all page and pro.mydr.pl returns 404. The only RFC 9116 file in the group sits on the consumer brand znanylekarz.pl: 44 bytes, one Contact: line, no Expires field, which the RFC requires. That is an observation about a channel, not a claim about cause. There is no evidence anyone ever tried to report anything.

How do companies find out they have been breached?

In 2025, only 52% of organisations first detected malicious activity themselves. 34% were told by an outside entity such as law enforcement or a CERT, and 14% were told by the attacker, usually in a ransom note (Mandiant M-Trends 2026, 2026). Median dwell time was 14 days: 9 days when found internally, 25 days when someone else found it first, up from 11 the year before.

That gap is the cost of having no way to be told.

Change Healthcare: 190 million people, one unfinished migration

UnitedHealth’s FY2024 10-K states “approximately 190 million” individuals. The larger 192.7 million figure comes from the HHS OCR breach portal and trade press, not from any SEC filing, and the count filed with OCR grew from a 500-person placeholder over roughly eighteen months.

The root cause is in sworn testimony from CEO Andrew Witty: on 12 February 2024 criminals used compromised credentials to reach a Citrix portal that “did not have multifactor authentication,” moved laterally, and exfiltrated data between 17 and 20 February. Ransomware landed on 21 February, nine days after entry. Several outlets blamed CitrixBleed; no primary source supports that. Asked why an external-facing server had no MFA, UnitedHealth told the Senate that “the server at issue was a legacy Change Healthcare server, and our team was working to bring this server up to UHG’s standards.” The acquisition had closed sixteen months earlier. The Item 1.05 Form 8-K came one day after detection; individual letters to affected people began in late July 2024, roughly five months after the records moved.

A channel existed and could not have helped. UnitedHealth’s vulnerability reporting policy, live since at least 2019, offered no bounty, no safe harbour and no response SLA. It prohibited “Active vulnerability scanning or testing,” excluded “violation of ‘best practices’,” and stated the company “will not disclose, discuss, or confirm security issues.” An internet-facing gateway missing MFA is exactly what a researcher needs active scanning to notice, and exactly what a triager can close as a best-practice violation.

Salesloft Drift: the breach a disclosure program could not have caught

This one is here because it cuts against the argument.

Between March and June 2025, an actor tracked as UNC6395 held Salesloft’s GitHub account, then pivoted into Drift’s AWS environment where customer OAuth tokens were stored, and used those legitimate tokens to reach customers’ Salesforce instances. Google Threat Intelligence Group states the issue “does not stem from a vulnerability within the core Salesforce platform.” Salesloft has never disclosed how the GitHub account was taken.

MFA and login monitoring were structurally bypassed, because the app was authorised and the tokens were real. What the actor wanted was credentials pasted into support tickets: Cloudflare found 104 live Cloudflare API tokens inside its own exfiltrated case text and rotated all of them, and the entire corpus had left in 3 minutes 22 seconds. Roughly five months passed between first GitHub access and disclosure on 20 August 2025, but only two days between the end of observed exfiltration and token revocation.

A vulnerability disclosure program would not have caught this. A GitHub account takeover and a centralised token vault inside a vendor’s own AWS estate are not externally observable, and the adjacent weaknesses are architecture decisions most VDP scopes exclude.

Compare a VDP-shaped defect in the same ecosystem, in the same quarter. Noma Security found ForcedLeak (CVSS 9.4) in Salesforce Agentforce, an expired domain still sitting in a CSP allowlist and buyable for about $5. Reported 28 July 2025, acknowledged 31 July, fixed 8 September, disclosed 25 September. Found from outside, reported, fixed, published.

Free Mobile: fined €42M, and four million victims had already left

CNIL’s January 2026 deliberations put the confirmed scale at 24,633,469 contracts: 19,460,891 mobile and 5,172,577 fixed, including names, addresses, dates of birth and IBANs for customers holding both services (CNIL, 2026). The attacker reached the subscriber-management tool through Free Mobile’s VPN, whose authentication CNIL found “not sufficiently robust,” faulting the absence of device authentication and of MFA for users. CNIL’s second finding was that the company had not deployed sufficient means to detect suspicious activity on that VPN, its internal network, or the subscriber tool. Holding logs is not a control.

The third finding is the one founders underrate. Free Mobile separately breached Article 5-1-e by keeping over fifteen million terminated contracts past five years, three million past ten. The arithmetic gives it away: 19.46 million mobile contracts exposed against roughly 15.51 million active mobile subscribers at 31 December 2024. Around four million more contracts were breached than the company had live customers. Retention policy was a security control, and its absence enlarged the blast radius by millions of people.

Access ran from 28 September to 22 October 2024, and CNIL records that the company was alerted on 21 October by an attacker who had entered its systems. Free notified CNIL inside the 72-hour deadline and still lost on Article 34, because CNIL held the notification email failed to let millions of affected people be reassured. Fines: €27M against FREE MOBILE, €15M against FREE.

free.fr serves a PGP-signed security.txt today, verified 12 August 2026: canonical URL, two contacts, an Expires date, an OpenPGP fingerprint. It has no Policy: line, so no scope and no safe harbour. A mailbox is not a program, and this intruder went to a criminal forum instead.

Tea: the finder was 4chan, and the fix came after publication

Tea Dating Advice confirmed that 72,000 images were accessed, including 13,000 verification selfies and government ID images (NBC News, 2025), the rest from posts, comments and messages, affecting only users who registered before February 2024 (TechCrunch, 2025). Its notice to the California attorney general is narrower: unauthorized access on or around 24 July 2025 to a storage location holding verification records, with indications of access to “most or possibly all” of them, exposing names, dates of birth, driver’s licence and passport numbers.

The root cause fits in the sentence 404 Media quoted from the 4chan post that started it: “No authentication, no nothing. It’s a public bucket.” No credential, no exploit chain, just a URL. Then a second flaw: a Firestore database of direct messages readable by any authenticated Tea user. 404 Media reported more than 1.1 million messages, verified against a sample; Tea never confirmed a number, saying only that some messages were accessed.

Two flaws, two channels, neither of them the company. The first went to 4chan on a Thursday evening, and consumer notification followed on 28 August 2025, a 35-day gap on the California register. The second went to a journalist: independent researcher Kasra Rahjerdi found the message database, chose not to publish, and routed it through 404 Media and to Tea, because that was the channel that worked. Tea disabled direct messages two days later, after publication. No regulator enforcement action has surfaced publicly, which is an absence of announcement, not proof of an absence of investigation.

The five side by side

Breach Confirmed scale Who told them first Reporting channel (probed 12 Aug 2026)
MyDr (PL, Aug 2026) None; attackers claim 18,814,422 PESELs The attackers, then journalists No security.txt; a 44-byte non-compliant file on a sibling brand
Change Healthcare (US, Feb 2024) ~190M (10-K); 192.7M on the HHS portal Nobody outside; the ransomware was the alarm Parent policy forbade active scanning; site returns 404
Salesloft Drift (SaaS, Aug 2025) Not published Unknown; no public source names a first detector 404, meta-refresh, soft-404; no public program
Free / Free Mobile (FR, Oct 2024) 24,633,469 contracts (CNIL) The attacker, on day 23 of a 24-day intrusion PGP-signed security.txt, no Policy: line
Tea (US, Jul 2025) 72,000 images, 13,000 of them IDs and selfies 4chan, then a journalist 404 on both domains

What the five have in common

One vendor, thousands of blast radii (3 of 5). MyDr is a processor for thousands of clinics, Change Healthcare a clearinghouse for a large share of US claims, Drift an app sitting inside hundreds of other companies’ Salesforce tenants. In all three, the compromised party was not the party whose customers were harmed. A 72-hour Article 33 clock now runs for thousands of small Polish clinics with no forensic visibility of their own.

Data kept long after it stopped being useful (3 of 5). Free is the regulator-proven case. Tea is the promise-versus-practice case: its privacy policy said verification selfies were deleted immediately after use, and 13,000 of them sat in a public bucket. MyDr is the hedged case. “Most likely historical, from 2024 and earlier years” is offered as reassurance, but read as a retention statement it says historical records were still reachable from production.

The victim was told, not the finder (4 of 5). MyDr: the attackers emailed the CEO. Free: the intruder ended twenty-three days of silence. Tea: 4chan, then a journalist. Change Healthcare: the encryption itself. Salesloft: unknown, and that gap should stay a gap. Mandiant’s numbers say this is the base rate, not a run of bad luck.

The identifiers you cannot rotate (3 of 5). You can rotate a password, an API key or an OAuth token; Cloudflare rotated 104 in a week. You cannot rotate a PESEL, an IBAN, a passport number or a date of birth. Polish state advice today reduces to freezing your PESEL in mObywatel and waiting for your clinic to write to you. Every extra year of retention is another year of permanent identifiers waiting in a system somebody will eventually reach.

The inherited asset (2 of 5). UnitedHealth closed the Change Healthcare acquisition in October 2022, and the unhardened gateway was still on the migration list in February 2024. MyDr was acquired in January 2023, and the group’s only RFC 9116 file sits on a different brand with a different contact address. Corporate integration and security-surface integration are separate projects, and the second one usually loses.

There was nowhere to send a report (5 of 5). This is the only characteristic that holds across all five, and two of them show why publishing a page is not the finish line. Change Healthcare proves a channel is not sufficient: a policy that forbids scanning and excludes best-practice findings filters out exactly the class of report that mattered. Salesloft proves a channel is not always relevant.

What a channel does buy is in Verizon’s own words about exposed data stores: they “are most commonly discovered by security researchers, who then attempt to make a notification if they can determine whose data it is. What we don’t know is how often other, less civic-minded people have encountered the same data, made a copy and quietly slipped away” (Verizon 2026 DBIR, 2026). The Tea bucket is that paragraph with a name attached.

Without a channel, the finder’s remaining options carry real personal risk. Students and a lecturer in Malta who emailed a company about vulnerabilities in October 2022 were raided by armed police three weeks later and pardoned only in July 2025. If your only intake is a support inbox and a legal team, you have published a policy, and it is the wrong one. More on that in safe harbor and legal threats to security researchers.

Where a disclosure program is already law, and where it is not

Be precise here, because most coverage is not.

EU Cyber Resilience Act (Regulation 2024/2847). Annex I Part II(5) requires manufacturers of products with digital elements to “put in place and enforce a policy on coordinated vulnerability disclosure.” Note the verb: a published page alone does not satisfy it. Article 14’s clock (24-hour early warning, 72-hour notification, 14-day final report for actively exploited vulnerabilities) applies from 11 September 2026, and the Regulation applies in full from 11 December 2027. It binds manufacturers placing products on the EU market, so a pure-SaaS web company is generally out of scope. Our breakdown of the CRA’s disclosure obligations has the detail.

NIS2 (Directive 2022/2555). Article 12 binds Member States and ENISA, not individual companies. Poland’s implementing KSC amendment entered into force on 3 April 2026, roughly seventeen months after the EU deadline, with registration due by 3 October 2026. The MyDr incident falls inside that window, before compliance and penalty deadlines bite.

UK PSTI (SI 2023/1007). Enforceable since 29 April 2024 for connectable products. Schedule 1 requires a published contact plus a statement of when a reporter gets acknowledgment and status updates, available without prior request, free of charge, and without requesting the reporter’s personal information. That last clause rules out gated forms and login-walled contact pages.

CISA BOD 20-01. Mandatory for US federal civilian agencies since 2020: a policy at the fixed path /vulnerability-disclosure-policy, with stated scope, permitted testing, and a clear statement that reports may be anonymous. CISA’s VDP Platform reported over 12,000 submissions across 51 agency programs cumulatively through 2023, producing over 2,400 valid disclosures.

Not a requirement. NIS2 does not oblige companies to run a VDP, and PCI DSS 4.0 does not either; PCI SSC’s guidance says disclosure programs “can help” with requirements 6.3.3 and 12.10.1. In US federal procurement there is no FAR obligation. The vehicle is H.R. 872, which passed the House on 3 March 2025 and remains unenacted as of 12 August 2026.

The economics do not wait for the law. IBM put the global average breach cost at a record $4.99M in 2026, up 12% (IBM Cost of a Data Breach 2026). HackerOne paid $81M in bounties across 1,950 programs in the year to 30 June 2025, but the top 100 programs took $51M of it, leaving roughly $16,000 a year for a typical program. A program with no bounties costs less again. And almost nobody publishes a contact: peer-reviewed Tranco scanning found security.txt on 34.0% of the top 100 domains but 1.0% of the top million in a January 2023 scan (Hilbig et al., ACM DTRAP), reaching only 1.25% of the top million by January 2025, with 44% of existing files RFC-conformant (URIports, 2025).

What to publish this week

None of this needs a bounty budget or a platform contract. The minimum that would have given a finder somewhere to go in all five cases:

  1. An RFC 9116 security.txt with a working Contact:, an Expires: date, and a Policy: line. Expires is mandatory, and details like it are why most published files fail conformance.
  2. A policy page stating scope, permitted testing, and safe harbour in plain language. Change Healthcare’s parent forbade the scanning a finder would have needed; Free has a mailbox with no policy at all.
  3. An acknowledgment commitment. Best practice, not statute: say how fast you will confirm receipt, and mean it.
  4. A named owner and a queue. Reports landing in a shared inbox get triaged by whoever is least busy, which is nobody.
  5. A timeline you can export. When a regulator or a journalist asks what you knew and when, “we handled it responsibly” is not evidence. A per-report chronology is.

The step-by-step version: how to set up a vulnerability disclosure program.

Running the intake without building it

Publishing a contact takes an afternoon. Running what arrives is the part that quietly fails, because a disclosure queue behaves like every other queue: it backs up, the clock runs, and nobody notices until an outsider does.

Kit’s CSIRT module is the operational layer for that and nothing more. It generates the security.txt and hosts a public reporting portal with your scope published beside it, so in-scope and out-of-scope targets are stated rather than implied. Incoming reports are validated against that scope, deduplicated, and put on an SLA clock with acknowledgment and per-severity resolution targets, plus at-risk tracking so a missed commitment surfaces before the reporter escalates. Researchers get persistent profiles and karma, so a repeat high-signal reporter is not stuck behind noise. Bounties are optional: the severity matrix, proposal voting, ledger and payout handoff are there if you pay, dormant if you do not. Every report carries an exportable timeline.

The limits matter as much as the features. Kit would not have prevented any of these five breaches. It is not EDR, not segmentation, not MFA, and it would not have surfaced Salesloft’s GitHub account takeover. It does not file to ENISA’s platform or perform your Article 33 and 34 notifications, and it is not legal advice. The honest claim is narrower: in four of these five cases the first person to know was not the company, and a published channel changes who finds out first.

Five companies, three continents, five different root causes. The only thing all five shared was that a person outside who wanted to tell them something had no supported way to do it. That is not a maturity gap or a budget problem. It is a missing interface, and it is the cheapest one on your roadmap.

Related articles

Ready to hire smarter?

Start free for 30 days. Cancel before it ends and you pay nothing. Set up your first hiring pipeline in minutes.

Start hiring free