18 million queries to the eWUŚ system and the personal data of more than 13 million people—that is the scale of the cyberattack revealed by the Regional Prosecutor’s Office in Poznań. Investigators identified the perpetrator, recovered the entire illegally obtained database, and the proceedings are currently at the final stage.

A huge number of queries to the eWUŚ system

The investigation in this case was initiated on April 8, 2024, on the basis of notifications submitted by the President of the National Health Fund. They concerned disclosed incidents involving excessive queries sent to the Electronic Verification of Patients’ Entitlements service, or eWUŚ, through entities providing medical services.

Investigators’ findings show that the perpetrators unlawfully gained access to the accounts of employees of selected medical entities using the MyDr platform.

They then used the program’s structure and implemented a script that made it possible to automatically send mass queries to the eWUŚ system.

The scale of the operation was enormous. As reported by the Regional Prosecutor’s Office in Poznań, the perpetrators sent approximately 18 million queries to the system.

Data of more than 13 million people

As a result of these actions, the eWUŚ system yielded the personal data of more than 13 million people.

The scope of the information obtained included:

  • first and last names,
  • PESEL number,
  • information about entitlement to health insurance or the lack thereof.

The case became particularly significant because of the scale of the database obtained. The perpetrators could also have used the data for further resale.

Investigators recovered the entire database

In the course of the proceedings, officers of the Central Bureau for Combating Cybercrime’s Board in Poznań, acting under the supervision of the Regional Prosecutor’s Office in Poznań, carried out measures that led to the recovery of the entire database of data illegally obtained from the National Health Fund.

According to the prosecutor’s office, these actions also prevented the further resale of the database.

Suspects identified. Charges filed

Investigators identified the perpetrator, whom the prosecutor charged, among other things, with creating computer programs designed to break through the security of IT systems and enable unauthorized access to the information stored in them.

The man also faced a charge related to breaching data security. He admitted to the acts alleged against him and provided detailed explanations.

However, this was not the only person to face charges in the case. Charges related to unauthorized access to data via the internet, after breaking through security systems, were also brought against four other people.

Two suspects were placed in temporary detention during the investigation. Currently, all suspects are subject to non-custodial preventive measures.

They face up to 12 years in prison

The acts alleged against the suspects are punishable by up to 8 and 12 years’ imprisonment.

The Regional Prosecutor’s Office in Poznań reported that the proceedings are currently at the final stage.

The investigation is being conducted by the Independent Cybercrime and Digitalization Division of the Regional Prosecutor’s Office in Poznań.