Concern over the security of personal information is becoming increasingly widespread in Poland, with new research showing that almost four in five people fear that compromised data could eventually lead to financial losses.
A 2026 study commissioned by the Credit Information Bureau, BIK, found that 79% of respondents were worried about the financial consequences that could follow a personal-data breach. More than one third, 37%, indicated a particularly high level of concern.
The findings point to a gradual change in how Polish consumers perceive cybercrime. Online fraud and identity theft are increasingly being regarded as risks that can affect ordinary households rather than isolated problems experienced by companies or particularly vulnerable internet users.
Personal experience of data-security incidents is also increasing. Around 33% of respondents said that either they or somebody close to them had encountered a situation involving compromised personal information. In 2022, the corresponding figure stood at 24%.
Direct exposure has also become significant, with 15% of people questioned in the latest study saying their own information had been involved in such an incident.
The results arrive against the backdrop of a major cybersecurity case affecting Poland’s healthcare sector. An incident involving technology provider MyDr has raised concerns over information relating to a very large number of patients and medical organisations.
Authorities have indicated that historical information associated with as many as approximately 18.8 million people could potentially have been exposed, together with data connected with more than 12,000 healthcare organisations. The precise number of individuals ultimately affected remains subject to investigation.
The scale of the case demonstrates how rapidly the consequences of a security failure can spread through an increasingly interconnected economy. A breach involving a technology supplier can potentially affect thousands of organisations using the same platform, even when those organisations’ own internal systems have not been directly attacked.
This creates an increasingly complicated risk environment for businesses. Companies routinely rely on external providers for cloud storage, customer management, payments, communications and specialist software. As these relationships multiply, protecting information increasingly depends not only on an organisation’s own cybersecurity standards but also on those maintained throughout its network of suppliers.
The same challenge is becoming relevant to the commercial property industry. Modern buildings increasingly depend on interconnected technology for access management, security, parking, visitor registration, energy monitoring, tenant services and building operations.
Office owners, shopping-centre operators, logistics developers, hotel groups and residential platforms can consequently hold or process substantial amounts of information about employees, tenants, customers, contractors and visitors. The expansion of digital building services therefore creates operational efficiencies while simultaneously increasing the number of systems that require protection.
The consequences of compromised information can also extend considerably beyond the original incident. Unlike a physical asset, personal information cannot simply be recovered and made unusable once an unauthorised party has obtained a copy.
Names, telephone numbers, addresses and other identifying information can subsequently be combined with information obtained from other sources. This can make fraudulent telephone calls, messages and emails appear considerably more credible because the person attempting the fraud already possesses genuine details about the intended victim.
That makes social manipulation an increasingly important component of cybercrime. Rather than attempting to obtain everything through a single technical attack, criminals can use previously compromised information to persuade individuals to reveal additional details or authorise transactions themselves.
For consumers, this means greater caution is required when receiving unexpected communications requesting information or financial action. Monitoring activity connected with an individual’s identity and credit history can also provide an indication that personal information is being used without permission.
For companies, however, the challenge is considerably broader. A serious security incident can generate regulatory investigations, legal costs, operational disruption and reputational damage while undermining confidence among customers and business partners.
The economic consequences can therefore continue long after the technical vulnerability responsible for the original incident has been repaired.
Poland’s growing public concern suggests that cybersecurity performance may increasingly influence consumer trust in businesses. Organisations collecting personal information are likely to face greater expectations to demonstrate not only that their own systems are appropriately protected, but that external technology providers handling the same information meet comparable standards.
The issue is particularly important as digitalisation spreads into industries that historically regarded cybersecurity primarily as a technology-sector concern. Healthcare, banking and telecommunications already manage large volumes of sensitive information, but property, retail, hospitality and logistics businesses are also becoming increasingly data dependent.
Buildings themselves are evolving into digital platforms. Access systems recognise employees and visitors, parking applications record movements, residential platforms manage tenant information and smart-building technology continuously exchanges operational data.
That evolution makes cybersecurity part of the wider discussion surrounding the resilience and management of real estate assets.
The latest Polish survey indicates that public awareness is moving in the same direction. With 79% of respondents now concerned about the possible financial consequences of compromised information and one third already having some direct or indirect experience of a data breach, confidence in the protection of personal information can no longer be taken for granted.
As businesses accumulate more information and become increasingly dependent on external technology providers, cybersecurity is moving beyond the boundaries of IT departments. It is becoming an issue of corporate governance, operational resilience and customer confidence, and one that companies across Poland’s increasingly digital economy will find progressively harder to ignore.