Daylila

Cybersecurity · Sunday, 23 August 2026

01 · Briefing · what happened

Nobody chose MyDr. Nineteen million people are in its breach anyway.

Cybersecurity 2 min 18 sources

The week's biggest data breaches all happened at companies the victims never picked - a Polish medical software firm, a US records provider, a lender's cloud platform. One bank traced its leak four links down the chain and would not name a single company in it.

19 million

people in the MyDr breach

at a software supplier, not a hospital [1]

3,756,469

people in the CareCloud breach

first estimated near 350,000 [2][3]

1.7 billion

logins stolen in six months

taken by password-stealing malware in early 2026 [14]

1,360,563

accounts exposed at Sakura Internet

a Japanese hosting company most of them never dealt with directly [15]

At a glance

  • Poland is investigating a break-in at MyDr, a medical software supplier, that may expose data on nearly 19 million people and 12,000-plus medical facilities. [1]
  • CareCloud, which sells records software to over 45,000 US healthcare providers, now says 3,756,469 people were hit - up from an early estimate near 350,000. [2][3]
  • Heights Finance was breached through a third-party cloud platform, not its own systems; it told Texas 734,828 people were affected and is notifying over 1.2 million. [5][6]
  • US Bancorp said a leaked-data claim traced to a fourth party outside its systems - its supplier's contractor - and would not name either firm. [9]
  • Toronto's SickKids hospital says staff and job-applicant data was taken through a flaw in a third-party application it shares with other organisations. [7][8]
  • Apollo Global says attackers were inside some of its cloud platforms for five days in July, part of a wave hitting finance, law and medical technology firms. [10][11]
  • A people-search site that promises private searches left 9 million image files open, including faces of people who never used it. [16]
  • Not every leak needs a chain: newly released documents show an NHS worker in Somerset opened up to 200 patient records and sent a screenshot to their partner. [17]

Forces in play

Records piling up at suppliers High

one software firm holds files reaching 12,000 Polish medical facilities, and another serves 45,000 US healthcare providers [1][2]

Stolen logins in circulation High

7.4 million devices infected with password-stealing malware in six months, 27% more than the half-year before [14]

Naming the real link Building

US Bancorp publicly traced a leak to a fourth party outside its own systems, which is further down the chain than companies usually admit [9]

Pre-emptive clean-up Easing

Poland is replacing the electronic passes that medical systems use to prove who they are on the national health platform, with no evidence any were stolen [1]

In play MyDr — Polish medical software supplier at the centre of a 19-million-person investigation CareCloud — US records provider whose breach count grew roughly tenfold US Bancorp — traced a leak four links out and named neither company CISA and the FBI — raised the Medusa ransomware victim count from 300 to more than 500

How it unfolded

  1. March a hacker spends six days inside one of CareCloud's cloud environments [2]
  2. May Heights Finance finds a break-in at a third-party cloud platform holding customer data [5]
  3. July attackers sit inside some of Apollo Global's cloud platforms for five days [10]
  4. Last week MyDr says it has identified and removed the cause of the intrusion [1]
  5. This week SickKids blames a third-party application; US Bancorp blames a fourth party [7][9]

Where this points

Watch whether Poland or MyDr publishes a count of who was actually in the exposed data. The 19 million figure is the ceiling of what the systems hold, not a confirmed tally. [1]

Full briefing

The arithmetic that turns one break-in into 19 million people

MyDr sells software to Polish doctors, clinics and practices. That is the whole reason a break-in at one private company may reach nearly 19 million people and more than 12,000 medical facilities [1]. Patients handed records to a clinic. The clinic runs MyDr. So the records ended up in one place no patient chose.

Polish authorities say the attackers reached historical data held through April 2024, and that it may not cover every MyDr customer [1]. The company says it removed the cause and has seen no sign the data was published [1]. Poland is also replacing the electronic passes that medical systems use to prove who they are on the national health platform [1]. Nobody says those were stolen. Swapping them just makes them useless if they were.

The same shape, three more times

CareCloud’s count moved the way these counts usually move. It was put near 350,000 at first; the federal health breach tracker now shows 3,756,469 [3][2]. The company sells records and billing software to over 45,000 US providers [2]. A hacker sat inside one of its cloud environments for six days in March [2][4].

Heights Finance shows how two true numbers disagree. The lender told Texas regulators 734,828 people were affected [5]; its wider notification covers more than 1.2 million [6]. One is a state filing, the other the full list. The break-in was at a third-party cloud platform the lender used for customer data, not its own loan systems [5][6].

Toronto’s SickKids hospital said staff, former staff and job applicants were exposed through a flaw in a third-party application used by the hospital “and other organizations” [7][8].

The clearest sentence of the week

A ransomware crew - criminals who scramble a company’s files and charge to unscramble them - named US Bancorp, America’s seventh-largest bank, as a victim [9]. The bank said the incident traced to “a fourth party event that occurred outside” its systems [9]. Not its supplier. Its supplier’s contractor. The bank declined to name either company [9].

What is claimed, and what is confirmed

A seller using the name TheHatman is offering 3.64 million employee records [13][12]. They are said to be taken from big companies’ Microsoft cloud accounts using stolen logins [13]. Tata Consultancy Services investigated and told India’s stock exchange it found no credible evidence of a breach [13]. It added that the details look at least four years old [13]. That is a claim, not a confirmed breach.

Stolen logins are the engine underneath all of it. Flashpoint counted 7.4 million devices infected with password-stealing malware in the first half of 2026 [14]. That is 27% more than the six months before, and it harvested 1.7 billion logins [14]. CISA and the FBI - the US cyber-defence agency and the federal police - now count more than 500 victims of the Medusa ransomware crew, up from 300 [18].

02 · Lesson · why it matters

The only company you can leave is the one that didn't lose your data

You pick the first link. Your records keep travelling, and the break-in happens further down, at a company nobody ever told you about.

How it works

  1. You hand your records to the one service you picked
  2. That service runs software it bought from someone else
  3. That supplier keeps the data with a contractor nobody told you about
  4. The break-in happens down there, at a company you cannot name
  5. You leave your provider for one using the same supplier underneath

The twist

Switching provider is the only lever most people have, and it moves the one link that did not lose anything. The replacement almost certainly buys from the same supplier underneath.

Where you've seen this

Food poisoning

you chose the restaurant; the bad batch came from its supplier's supplier

Renting a flat

you met the landlord; your bank statements sit with a referencing firm you never met

Job hunting

you applied to one hospital; your CV went into a careers product dozens of employers share

Air travel

you booked with one airline; another flies the plane and a third holds the booking

The catch

The chain is also the reason a small clinic can run modern records software at all - the same sharing that spreads the risk is what makes the service affordable.

Full lesson

The clinic you chose, and the company you didn’t

A person in Poland sat in a doctor’s waiting room and filled in a form. They chose the clinic. Maybe they compared two. That was the whole of the choosing they got to do.

The clinic, meanwhile, had made its own choice, about software. It bought a records system from a company called MyDr. Nobody in the waiting room was consulted, and nobody would have expected to be. This week Polish authorities began investigating a break-in at that company that may reach nearly 19 million people.

Consent was collected at the front desk. The data kept going.

Why the number is 19 million and not 1,500

A single clinic holds maybe a few thousand records. A software company that serves 12,000 medical facilities holds all of theirs at once.

Nothing sinister put them there. It is just where the work happens. A small practice cannot build a records system, so it rents one, and renting one means the records live on the supplier’s machines. The same week, an American records company told regulators that 3.7 million people were in its breach, having first estimated 350,000. It sells to more than 45,000 healthcare providers.

The count is not a measure of how badly one company was defended. It is a measure of how many people’s records were sitting in the same place when someone got in.

The word “fourth”

The clearest sentence of the week came from a bank. After criminals listed US Bancorp as a victim, the bank said the incident traced to a “fourth party event” outside its own systems.

Count the links. You are the first. The bank is the second. The bank’s supplier is the third. The supplier’s contractor is the fourth, and that is where the data went missing. The bank would not name the third or the fourth.

That is not evasion so much as an admission. Even the institution at the centre of it describes the place your records were lost as a company it will not, or cannot, name.

Most people, told their data leaked, reach for the one action available: leave. Change lender. Switch clinic. Close the account.

Look at where that lever actually acts. It acts on the second link, the one you can see, the one whose name is on the letter. The break-in happened at the third or the fourth. The company you are leaving may have lost nothing at all. Heights Finance said plainly that its own loan systems were untouched. The theft was from a cloud platform it rented.

And the provider you switch to has to run on something. In a market where a handful of suppliers serve tens of thousands of clinics or lenders, the replacement is quite likely buying from the same place. You have moved. Your data has not.

The one number that is actually yours

There is one quantity a person sets themselves, and it is set at the front desk, in the moment before anything is handed over. How much goes onto the form.

Whatever is written there is what propagates. It is copied to the supplier, and from the supplier to the contractor, and it is what sits in the file when someone gets in three companies away. A field left blank does not travel, because there is nothing to travel.

That is not a solution, and it would be dishonest to dress it up as one. Most of what is on a medical form has to be there. It is simply the only point in the chain where an ordinary person is the one deciding.

Everyone is standing downstream of someone

It is tempting to read this as institutions being careless with people. Some of it is. But the hospital is also downstream. Toronto’s SickKids said the flaw was in a third-party application it uses along with other organisations. The hospital did not write it and cannot inspect it. It learned about the problem the way its job applicants did.

The bank was downstream of its supplier. The supplier was downstream of a contractor. Each one made a reasonable choice about the link directly in front of it, which is the only link any of them could see clearly.

Nobody in the chain is looking at the whole of it. That includes the people at the top of it, and it certainly includes the person filling in the form.

03 · Lab · your turn

Four Links Down

Hand over three forms and watch how far the copies travel past the only company you actually chose.

04 · Hope · carry this

A bank said this week that its leak sat four links from its own systems, and a country changed its medical keys before anyone proved they were stolen. A chain somebody is willing to point at is a chain somebody can fix.

Across the beats