This article is a part of Poland Unpacked. Weekly intelligence for decision-makers
Revolut, MyDr and, most recently, enel-med have joined the inglorious list of organisations that lost control of data. These cases raise questions about how data leaks happen and whether they could have been prevented.
The case of MyDr – a company that, according to Poland’s Personal Data Protection Office (UODO), may have served several thousand medical facilities across the country – has once again drawn business attention to the importance of data security. MyDr fell victim to a cyberattack, and cloud-stored data relating to 19m Poles was leaked.
Each medical facility working with the company informed its customers by email about the “incident”. The case was referred to UODO, which announced inspections.
The Revolut leak was different in nature. Fraudsters impersonated a government agency, using its email domain to gain access to customer data. The company said, however, that funds held in customer accounts were not affected.
Human error, inadequate staff training, a hacker attack or insufficient technological safeguards? Against the backdrop of recent incidents and tighter data-protection rules, we asked experts how companies lose control of data.
Companies without a plan for an “incident”?
In MyDr’s case, UODO inspectors will examine the technical and organizational measures used by the company. They will also look at whether the safeguards were tested against threats and whether the company conducted a data-leak risk assessment.
Our experts have no doubt that in the 21st century companies should no longer ask whether such an incident might happen. They should ask when it will happen.
“Every company generates huge amounts of data and needs ever more storage space, often across different environments. At the same time, obligations related to storing information, including sensitive data, are increasing. As companies make greater use of technologies such as AI and cloud services, maintaining control over where data is located and how it is used becomes increasingly important.
“There is a reason why people now talk about an ‘assume breach’ approach. Companies should take the possibility of an incident for granted and prepare in a way that limits its impact on the business. Many organizations still struggle to develop and regularly test incident-response procedures and plans for recovering data and systems,” says Tomasz Krajewski, technical sales director for Eastern Europe at Veeam.
Veeam’s latest survey shows that almost half of IT leaders fear a cyberattack. Some 60% of respondents believe AI-enabled attacks may prove more dangerous than traditional ransomware intrusions, in which criminals block access to systems and demand payment.
It is therefore unsurprising that 45% of IT leaders say they plan to increase spending on protection this year.
When data trains artificial intelligence…
AI in business is undoubtedly a sign of the times and evidence of innovation. But an increasing number of specialists also see it as a source of risk.
“Companies are creating a new channel for silent information leaks – so-called shadow AI. Employees copy parts of contracts, client documents, source code, financial data or personal information into private or public AI tools that the organization has not approved and does not control,” says Marek Ballaun, attorney-at-law, partner at OCTO GRC and Senior Associate & CISO at law firm OCTO Legal.
Krajewski adds that these data can then be used to train artificial intelligence, which “does not forget”.
Employees will use AI, but they should do so within a secure, trusted environment that gives the organization adequate control and visibility.
“AI tools are becoming a permanent part of everyday work. Clear rules governing their use, proper supervision and control are becoming increasingly important. Without the right safeguards and employee training, companies risk exposing sensitive information.
“They also risk data being used in ways that breach internal policies or regulatory requirements. Employees will use AI, but they should do so in a secure and trusted environment that gives the organization appropriate control and visibility,” says the Veeam representative.
GDPR, the AI Act and NIS2
Since the introduction of GDPR, personal-data protection should have been a core concern across different business functions.
For more than eight years, the rules have required data controllers to ensure appropriate technical and organizational measures proportionate to risk. Even then, the law required companies to verify who they entrusted customer data to.
The AI Act, in turn, has drawn business attention to the risks associated with the use of artificial intelligence. From a data perspective, an important obligation is to train employees operating AI systems and assess the level of risk associated with processing particular types of data.
According to our experts, however, the NIS2 Directive may provide the clearest guide for companies.
“The amendment to Poland’s National Cybersecurity System Act implementing NIS2 entered into force on April 3, 2026. It brought new groups of entities under obligations related to managing the risk of incidents. The rules also require organisations to consider the security of suppliers and service providers.
“Responsibility for organizing a cybersecurity system is becoming clearly a management issue, rather than something belonging exclusively to the IT department. NIS2 and domestic rules do not introduce an entirely new idea. The main change is that principles long known from data protection, risk management and security standards are now starting to be enforced.
“There are obligations to report incidents, manage risk systematically, introduce controls and establish management accountability,” Ballaun explains.
Responsibility for organizing cybersecurity is becoming clearly a management issue, not just an IT issue.
Krajewski argues that every company – not only those directly covered by NIS2 – should make sure it can withstand and recover from an incident.
“Every organization should have documented and regularly tested disaster-recovery procedures. This is a plan designed to ensure that after a failure, cyberattack or other disruption, critical systems and data can be restored quickly and effectively.
“This requires a clear strategy defining how the organization will restore systems, verify data integrity and maintain continuity of customer service. Today, the question is no longer whether a company will face a cyber incident, but whether it will be prepared to recover effectively from one,” Krajewski says.
Good to know
Personal-data protection in numbers
12,827. That is how many complaints UODO received in 2025.
For comparison, there were 8,318 reports of personal-data breaches in 2021, 6,995 in 2022 and 8,056 in 2024. In 2025, UODO therefore received 61% more individual complaints than in 2024.
The most common complaints concerned sharing data in email correspondence, sending correspondence to unauthorized recipients and processing data through video surveillance.
Other cases involved data processing in connection with debt collection, marketing, processing by banks and – notably – employers disclosing information about an employee’s health to colleagues.
In education, recurring complaints concerned disclosing information about children, transferring data through electronic school registers and publishing pupils’ images.
In 2025, data controllers reported 22,435 personal-data breaches to UODO. In 2024, the figure was 14,842. The head of UODO therefore received 51% more breach notifications.
Among the most common incidents reported by data controllers were incorrectly addressed correspondence, disclosure of data to the wrong person, inadequate anonymization or accidental publication, lost correspondence, unauthorized access to databases, theft of data-storage devices and malicious software compromising the confidentiality, integrity or availability of personal data.
Is the human being the weakest link?
In response to our questions, Revolut confirmed that an external party used an email address in the legitimate domain of a government institution to submit fraudulent requests for information.
Importantly, financial institutions are legally required to comply with official requests from law-enforcement authorities or government agencies. Revolut therefore believed that it was dealing with a genuine public authority.
“After discovering the matter, we immediately blocked the address and notified the relevant government institution, as well as law-enforcement authorities, data-protection authorities and financial-market regulators.
“Neither Revolut’s systems nor customer funds were compromised. We contacted the limited number of individuals affected by the incident directly to inform them and provide support,” the company said in a statement sent to us.
“Many so-called cyber incidents result from a combination of technological and human factors. Cybercriminals increasingly use AI-supported techniques, including advanced impersonation and social engineering.
“Organizations therefore need to prepare employees to recognize potential threats and respond appropriately. Even with well-secured infrastructure, regular training, awareness-building and clearly defined procedures remain necessary.
“Cyber resilience requires both effective technology and people who are aware and prepared,” Krajewski says.
Cybersecurity meets the law
“The most obvious target of a cyberattack is the human being. That is where phishing works – impersonating contractors, managers or IT administrators.
“A more advanced version is spear-phishing: a message crafted for a specific person and using information about their position, colleagues or current project. Such information can come from public sources or from previous leaks,” Ballaun says.
That is the second target for hackers, after technology itself. But as our expert adds, in cases such as Revolut, both can fail: people and systems.
“You can assume that an institution such as Revolut has procedures for handling requests submitted by public authorities. We do not know the exact course of that process or which elements failed.
“What we do know is that the fraudulent requests came from an address using a real government domain. That is a very important distinction.
“The employee did not receive a message from a domain merely resembling the real one, for example with one letter changed. They received a message that had one of the most important characteristics normally used to confirm authenticity,” Ballaun explains.
He adds that companies he advises regularly receive requests for information and documents from public authorities.
“Not every such request is correct simply because it was genuinely sent by an authority. Requests sometimes lack a properly stated legal basis, seek a broader range of data than necessary or are submitted under a procedure that does not provide a legal basis for obtaining the requested information.
“So when transferring data outside the organization, two questions are actually necessary. First: does the person making the request really represent the institution they claim to represent? Second: does that institution actually have the right to receive this particular scope of data?” the expert concludes.
The lesson? Clear roles and a strategy
After an incident, companies often change systems, increase security spending or invest in audits.
Experts agree, however, that organizations still struggle not only with strategy, but also with the division of responsibilities. Is corporate resilience still solely the responsibility of the IT department?
Bartłomiej Tkaczyk, partner at law firm LEGALLY.SMART, adds that when an attack occurs, companies often also face a problem with decision-making.
“In the first hours after a cyberattack, there should be no doubt about who makes decisions, what information the supplier must provide and what each party is responsible for,” he explains.
Tkaczyk adds that cyberattacks are becoming a problem for the entire organization, even if the technology itself is supplied by an external provider.
“The point is not for the management board or senior executives to replace cybersecurity specialists. But they should know where the key data is located, who has access to it and how the organization will respond if an external system fails.
“Today, this is part of informed risk management, not merely a technical issue,” Tkaczyk concludes.
Key Takeaways
- A data leak does not necessarily mean that someone hacked into a system. The Revolut case shows that the weakest link can be human. In this instance, fraudsters submitted fake requests using the domain of a public institution.
- Data protection is no longer solely the responsibility of the IT department. It involves procedures, employees, management, suppliers, risk assessment and the way an organization responds to incidents. Rules such as NIS2 further strengthen the organizational dimension of cybersecurity.
- AI creates a new channel of risk, while also requiring new capabilities. Employees may transfer information to AI agents without proper oversight, so companies need to control how these systems are used. The AI Act is one of the regulations addressing such practices.
