Cybersecurity · Sunday, 23 August 2026
01 · Briefing · what happened
Nobody chose MyDr. Nineteen million people are in its breach anyway.
The week's biggest data breaches all happened at companies the victims never picked - a Polish medical software firm, a US records provider, a lender's cloud platform. One bank traced its leak four links down the chain and would not name a single company in it.
19 million
people in the MyDr breach
at a software supplier, not a hospital
3,756,469
people in the CareCloud breach
first estimated near 350,000
1.7 billion
logins stolen in six months
taken by password-stealing malware in early 2026
1,360,563
accounts exposed at Sakura Internet
a Japanese hosting company most of them never dealt with directly
At a glance
-
Poland is investigating a break-in at MyDr, a medical software supplier, that may expose data on nearly 19 million people and 12,000-plus medical facilities.
[1] -
CareCloud, which sells records software to over 45,000 US healthcare providers, now says 3,756,469 people were hit - up from an early estimate near 350,000.
[2] [3] -
Heights Finance was breached through a third-party cloud platform, not its own systems; it told Texas 734,828 people were affected and is notifying over 1.2 million.
[5] [6] -
US Bancorp said a leaked-data claim traced to a fourth party outside its systems - its supplier's contractor - and would not name either firm.
[9] -
Toronto's SickKids hospital says staff and job-applicant data was taken through a flaw in a third-party application it shares with other organisations.
[7] [8] -
Apollo Global says attackers were inside some of its cloud platforms for five days in July, part of a wave hitting finance, law and medical technology firms.
[10] [11] -
A people-search site that promises private searches left 9 million image files open, including faces of people who never used it.
[16] -
Not every leak needs a chain: newly released documents show an NHS worker in Somerset opened up to 200 patient records and sent a screenshot to their partner.
[17]
Forces in play
one software firm holds files reaching 12,000 Polish medical facilities, and another serves 45,000 US healthcare providers
7.4 million devices infected with password-stealing malware in six months, 27% more than the half-year before
US Bancorp publicly traced a leak to a fourth party outside its own systems, which is further down the chain than companies usually admit
Poland is replacing the electronic passes that medical systems use to prove who they are on the national health platform, with no evidence any were stolen
How it unfolded
- March a hacker spends six days inside one of CareCloud's cloud environments [2]
- May Heights Finance finds a break-in at a third-party cloud platform holding customer data [5]
- July attackers sit inside some of Apollo Global's cloud platforms for five days [10]
- Last week MyDr says it has identified and removed the cause of the intrusion [1]
- This week SickKids blames a third-party application; US Bancorp blames a fourth party [7][9]
Where this points
Watch whether Poland or MyDr publishes a count of who was actually in the exposed data. The 19 million figure is the ceiling of what the systems hold, not a confirmed tally.
Full briefing
The arithmetic that turns one break-in into 19 million people
MyDr sells software to Polish doctors, clinics and practices. That is the whole reason a break-in at one private company may reach nearly 19 million people and more than 12,000 medical facilities
Polish authorities say the attackers reached historical data held through April 2024, and that it may not cover every MyDr customer
The same shape, three more times
CareCloud’s count moved the way these counts usually move. It was put near 350,000 at first; the federal health breach tracker now shows 3,756,469
Heights Finance shows how two true numbers disagree. The lender told Texas regulators 734,828 people were affected
Toronto’s SickKids hospital said staff, former staff and job applicants were exposed through a flaw in a third-party application used by the hospital “and other organizations”
The clearest sentence of the week
A ransomware crew - criminals who scramble a company’s files and charge to unscramble them - named US Bancorp, America’s seventh-largest bank, as a victim
What is claimed, and what is confirmed
A seller using the name TheHatman is offering 3.64 million employee records
Stolen logins are the engine underneath all of it. Flashpoint counted 7.4 million devices infected with password-stealing malware in the first half of 2026
02 · Lesson · why it matters
The only company you can leave is the one that didn't lose your data
You pick the first link. Your records keep travelling, and the break-in happens further down, at a company nobody ever told you about.
How it works
- You hand your records to the one service you picked
- That service runs software it bought from someone else
- That supplier keeps the data with a contractor nobody told you about
- The break-in happens down there, at a company you cannot name
- You leave your provider for one using the same supplier underneath
The twist
Switching provider is the only lever most people have, and it moves the one link that did not lose anything. The replacement almost certainly buys from the same supplier underneath.
Where you've seen this
Food poisoning
you chose the restaurant; the bad batch came from its supplier's supplier
Renting a flat
you met the landlord; your bank statements sit with a referencing firm you never met
Job hunting
you applied to one hospital; your CV went into a careers product dozens of employers share
Air travel
you booked with one airline; another flies the plane and a third holds the booking
The catch
The chain is also the reason a small clinic can run modern records software at all - the same sharing that spreads the risk is what makes the service affordable.
Full lesson
The clinic you chose, and the company you didn’t
A person in Poland sat in a doctor’s waiting room and filled in a form. They chose the clinic. Maybe they compared two. That was the whole of the choosing they got to do.
The clinic, meanwhile, had made its own choice, about software. It bought a records system from a company called MyDr. Nobody in the waiting room was consulted, and nobody would have expected to be. This week Polish authorities began investigating a break-in at that company that may reach nearly 19 million people.
Consent was collected at the front desk. The data kept going.
Why the number is 19 million and not 1,500
A single clinic holds maybe a few thousand records. A software company that serves 12,000 medical facilities holds all of theirs at once.
Nothing sinister put them there. It is just where the work happens. A small practice cannot build a records system, so it rents one, and renting one means the records live on the supplier’s machines. The same week, an American records company told regulators that 3.7 million people were in its breach, having first estimated 350,000. It sells to more than 45,000 healthcare providers.
The count is not a measure of how badly one company was defended. It is a measure of how many people’s records were sitting in the same place when someone got in.
The word “fourth”
The clearest sentence of the week came from a bank. After criminals listed US Bancorp as a victim, the bank said the incident traced to a “fourth party event” outside its own systems.
Count the links. You are the first. The bank is the second. The bank’s supplier is the third. The supplier’s contractor is the fourth, and that is where the data went missing. The bank would not name the third or the fourth.
That is not evasion so much as an admission. Even the institution at the centre of it describes the place your records were lost as a company it will not, or cannot, name.
The lever that moves the wrong link
Most people, told their data leaked, reach for the one action available: leave. Change lender. Switch clinic. Close the account.
Look at where that lever actually acts. It acts on the second link, the one you can see, the one whose name is on the letter. The break-in happened at the third or the fourth. The company you are leaving may have lost nothing at all. Heights Finance said plainly that its own loan systems were untouched. The theft was from a cloud platform it rented.
And the provider you switch to has to run on something. In a market where a handful of suppliers serve tens of thousands of clinics or lenders, the replacement is quite likely buying from the same place. You have moved. Your data has not.
The one number that is actually yours
There is one quantity a person sets themselves, and it is set at the front desk, in the moment before anything is handed over. How much goes onto the form.
Whatever is written there is what propagates. It is copied to the supplier, and from the supplier to the contractor, and it is what sits in the file when someone gets in three companies away. A field left blank does not travel, because there is nothing to travel.
That is not a solution, and it would be dishonest to dress it up as one. Most of what is on a medical form has to be there. It is simply the only point in the chain where an ordinary person is the one deciding.
Everyone is standing downstream of someone
It is tempting to read this as institutions being careless with people. Some of it is. But the hospital is also downstream. Toronto’s SickKids said the flaw was in a third-party application it uses along with other organisations. The hospital did not write it and cannot inspect it. It learned about the problem the way its job applicants did.
The bank was downstream of its supplier. The supplier was downstream of a contractor. Each one made a reasonable choice about the link directly in front of it, which is the only link any of them could see clearly.
Nobody in the chain is looking at the whole of it. That includes the people at the top of it, and it certainly includes the person filling in the form.
03 · Lab · your turn
Four Links Down
Hand over three forms and watch how far the copies travel past the only company you actually chose.
04 · Hope · carry this
A bank said this week that its leak sat four links from its own systems, and a country changed its medical keys before anyone proved they were stolen. A chain somebody is willing to point at is a chain somebody can fix.
More from Cybersecurity