{"id":20745,"date":"2026-08-14T08:50:31","date_gmt":"2026-08-14T08:50:31","guid":{"rendered":"https:\/\/bizonews.com\/pl\/data-leak-of-19-million-people-do-you-have-an-unblocked-pesel-here-is-what-you-need-to-know\/"},"modified":"2026-08-14T08:50:37","modified_gmt":"2026-08-14T08:50:37","slug":"data-leak-of-19-million-people-do-you-have-an-unblocked-pesel-here-is-what-you-need-to-know","status":"publish","type":"post","link":"https:\/\/bizonews.com\/pl\/data-leak-of-19-million-people-do-you-have-an-unblocked-pesel-here-is-what-you-need-to-know\/","title":{"rendered":"Data leak of 19 million people: Do you have an unblocked PESEL? Here is what you need to know"},"content":{"rendered":"<p>Following a massive data leak involving MyDr systems, experts explain the real financial risks of compromised personal information, the importance of blocking your PESEL number, and what steps to take if fraudsters strike.  <\/p>\n<h4>The Reality of the 19 Million Data Leak<\/h4>\n<p>A data leak involving information regarding up to 19 million people has sparked a wave of questions about the financial security of Poles. Simply having a PESEL number along with a first and last name is usually not enough today to successfully take out a loan, but experts warn that the acquired data can be used in more complex fraud attempts.<\/p>\n<p>The most serious problem after the disclosure of millions of people&#8217;s data may not be an immediate attempt to take out a loan in someone else&#8217;s name. Marcin Jaworski from the Financial Ombudsman&#8217;s Office points out in an interview with money.pl that the PESEL number alone, even combined with a first and last name, generally does not give a criminal sufficient opportunity to successfully conclude a credit or loan agreement under current conditions. Financial institutions apply additional verification mechanisms, both in branches and during online agreements.<\/p>\n<h4>Social Engineering Risks and the MyDr Incident<\/h4>\n<p>This does not mean, however, that the disclosed information can be considered harmless. Criminals can use real data to prepare forged documents and, above all, to conduct more credible social engineering attacks. A person calling a victim who knows their PESEL number, first name, last name, or other details can much more easily impersonate a bank employee, office worker, or official. UODO points to similar threats, recommending special caution regarding SMS messages, emails, and phone calls aimed at extracting further information following the MyDr incident.<\/p>\n<p>The matter gained particular significance after the disclosure of a cyberattack on the systems of MyDr, a supplier of electronic medical records solutions. According to information provided in connection with the incident, the database could have included data on nearly 19 million people, and about 12,000 medical entities used the platform. Information at risk of disclosure included not only basic identification data but also health-related data, including information about medications and prescriptions.<\/p>\n<p>The scale of the breach has not yet been finally determined. On August 13, the President of the Personal Data Protection Office announced the initiation of an inspection at MyDr. Controllers are to check the technical and organizational safeguards applied by the company, the manner in which risk analysis is conducted, and whether security measures were regularly tested in connection with changing threats. UODO notes that medical facilities using MyDr solutions are reporting violations, while the exact scale of the event is still being determined.<\/p>\n<h4>Blocking the PESEL Number and Financial Consequences<\/h4>\n<p>The Ministry of Digital Affairs and representatives of the banking sector encourage blocking the PESEL number. This can be done via the mObywatel application or at a municipal office. This mechanism is particularly important when concluding financial agreements, as banks, lending institutions, and other entities covered by regulations must check the PESEL status before performing specific activities.<\/p>\n<p>Blocking the number has a very specific effect. If a financial institution were to grant a credit or loan despite an active block, the person whose data was used should, as a rule, not bear responsibility for repaying such an obligation. The Polish Bank Association recalled after the cyberattack on MyDr that checking the block register is one of the basic mechanisms aimed at limiting the effects of identity theft.<\/p>\n<p>The PESEL itself should not be treated as the only safeguard. Data cited by money.pl shows that 69 percent of Poles declare blocking their number after it is stolen, but only 33 percent would subsequently monitor their credit history. Experts emphasize that stolen data may also be used in other types of fraud, and even after blocking the number, it is worth monitoring unusual messages, contact attempts, and information regarding financial obligations.<\/p>\n<h4>Handling Fraud Demands and Bank Withdrawals<\/h4>\n<p>Blocking the PESEL significantly limits the risk, but the Financial Ombudsman&#8217;s expert does not rule out situations where a fraudster manages to bypass the applied procedures. If an agreement is concluded using someone else&#8217;s data and the bank or lending company starts demanding repayment, the victim should file a complaint directly with the entity that granted the financing. It should be clearly indicated that the agreement was not concluded by the person whose data was used, and demand the suspension of collection activities while the matter is being clarified.<\/p>\n<p>If the complaint is rejected, it is possible to turn to the Financial Ombudsman for intervention or amicable proceedings. It is also important that even with an unblocked PESEL, the creditor must prove that the person indicated in the agreement actually made the declaration of intent leading to the creation of the obligation. The lack of prior blocking of the number may thus complicate the victim&#8217;s situation, but in itself does not mean automatic liability for an obligation incurred by a criminal.<\/p>\n<p>Blocking the PESEL number also affects certain operations performed by the data owner. For cash withdrawals at a bank branch exceeding three times the minimum wage, an additional security mechanism applies. The minimum wage in 2026 is 4,806 PLN gross, so three times this amount is 14,418 PLN.<\/p>\n<p>If a customer wishes to withdraw more than the indicated threshold at a bank teller window while their PESEL remains blocked, the bank should not execute the operation immediately. A 12-hour waiting period applies. This mechanism is intended to give a potential fraud victim additional time to realize they may be acting under manipulation. The restriction does not cover regular ATM withdrawals.<\/p>\n<h4>Managing Temporary Unblocking and Long-Term Threats<\/h4>\n<p>An active block does not mean the number cannot be temporarily unblocked. This is necessary, among other times, when the PESEL owner wants to take out a loan or credit themselves, open a bank account, or use certain forms of deferred payment. After completing the planned activity, protection can be reactivated. However, it must be remembered that at least 30 minutes must pass from revoking the block to the possibility of blocking the number again.<\/p>\n<p>Experts also warn against the belief that the threat passes a few days after a cyberattack. Once acquired, data can remain in circulation for a very long time. It does not have to be used immediately\u2014it can be used for a fraud attempt after many months or even years. Therefore, securing the PESEL and caution against attempts to extort further data should be permanent.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Following a massive data leak involving MyDr systems, experts explain the real financial risks of compromised personal information, the importance of blocking your PESEL number, and what steps to take if fraudsters strike. The Reality of the 19 Million Data Leak A data leak involving information regarding up to 19 million people has sparked a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":20746,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"wpai_generated_summary":"","footnotes":""},"categories":[10],"tags":[],"class_list":["post-20745","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech"],"_links":{"self":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts\/20745","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/comments?post=20745"}],"version-history":[{"count":0,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/posts\/20745\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/media\/20746"}],"wp:attachment":[{"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/media?parent=20745"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/categories?post=20745"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bizonews.com\/pl\/wp-json\/wp\/v2\/tags?post=20745"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}