Cyberattacks in Poland. Examples of cyberattacks on Polish companies

06 October 2025

Cyberattacks in Poland have reached a record scale. In 2024 alone, the CERT Polska team recorded over 600,000 reports of cyber incidents – an increase of 62% compared to the previous year. The most frequently reported type of attack was phishing. New forms of social engineering fraud have also gained popularity, such as fake summons from the police, fines with QR codes, or messages "from a child" from a new number.

We see here a map targeted at Poland – says Arkadiusz Sadowski, a cybersecurity expert, during the ODO 24 training. The screen displays in real-time points representing attacks from around the world. By 10:00 AM, over 69 thousand attempts had been recorded – the day before, there were 174 thousand.

Attack on local government – real documents and data

In April 2024, the media reported a cyberattack on a Polish local government office. Hackers published documents and data that were said to originate from internal systems: contracts, personnel data, accounts, email addresses. Although the office did not confirm the leak, experts suspect that there was an infection with malicious software – it only took one click to open a pathway for the attackers to the organization's resources.

PAP – false dispatch about mobilization

In May 2024, a false message about nationwide military mobilization was published on the PAP service. Although it was quickly removed, it caused a stir and reactions from the authorities. PAP confirmed that there was a cyberattack on the editorial system, and the incident may be part of a disinformation campaign.

Most common attack: phishing. Who do criminals most often impersonate?

According to the CERT Polska 2024 report, phishing accounts for 40% of all incidents. In 2024, there were over 40 thousand cases, and the most common impersonations by criminals were:

  • OLX – 9,865 cases,
  • Allegro – 4,053 cases,
  • Facebook – 3,871 cases.

The goal is one: to obtain login credentials, card data, or to take over accounts for further attacks. Learn more cases

E-learning: cybersecurity

Not just email. New forms of social engineering fraud

CERT Polska has recorded an increasing number of attacks utilizing messaging apps, SMS, and physical media. Here are selected scenarios from 2024:

  • Child fraud (WhatsApp): “Mom, this is my new number. I urgently need money.”
  • Fake police summons: information about criminal proceedings and an offer to “settle the matter” for a fee.
  • Fake QR codes on cars: the link leads to a payment page.
  • CAPTCHA with malware: fake verification pages that execute malicious commands on the computer.

In 2024 alone, Poles reported over 355 thousand suspicious SMS messages to CERT, representing a 60% increase compared to the previous year. Thanks to these reports, 1.5 million malicious messages were blocked.

What does an attack look like in practice?

During the ODO 24 training, a security expert demonstrates how to create a fake login page for Microsoft 365 or Facebook in 3 minutes using open-source tools.

The page looks identical to the original. The only difference – seemingly subtle – is the address (micros0ft-login.pl). Data entered by the victim is saved to a file on the attacker's computer. Cost of the attack? 5 PLN per domain. Risk? Loss of control over the account or system.

Ransomware remains a threat – despite a decrease in the number of incidents

In 2024, CERT Polska registered 147 ransomware incidents, of which:

  • 87 involved companies,
  • 35 involved private individuals,
  • 25 involved public institutions.

GDPR training in IT
Migrations, clouds, systems.
GDPR in IT.
GDPR training in IT for Data Protection Officers and IT managers and staff. We invite you!
CHECK DATES
Despite a slight decrease (-8% year-on-year), ransomware remains the most destructive type of cyberattack - stealing and encrypting data, and then demanding a ransom, which paralyzes the company's operations.

Why are cyberattacks in Poland becoming increasingly effective?

According to the Microsoft Digital Defense Report 2024, attackers are increasingly relying less on advanced codes, programs, or techniques. Over 90% of attacks start with... a human.

  • 56% of phishing attacks use spoofed links,
  • 25% are QR attacks (smishing),
  • 19% involve malicious attachments (Word, Excel, PDF).

Hackers are increasingly employing what is known as AiTM phishing. This is a type of attack in which hackers can intercept a login session even when the user is using two-factor authentication (MFA).

In practice, it works like this: the victim lands on a fake login page that closely resembles the real one. When they enter their username, password, and one-time code from their phone, the attacker steals this information and then inputs it into the real system. As a result, the attacker can use the account as if they were the owner – without needing to enter additional security codes.

The solution to this problem is physical U2F or FIDO2 keys, which completely eliminate the possibility of "intercepting" the login. Unlike SMS codes, they only work in conjunction with the legitimate site. Therefore, even if someone enters their information on a fake site, the key simply will not work, and the attack will fail.

Antivirus alone is not enough. How to protect your company?

Organizations in Poland are now implementing a zero trust model, which assumes that no one – not even an employee – should have default access without verification.

Effective protection methods include:

  • employee training (e-learning, phishing tests),
  • regularly checking the team's vigilance,
  • clear procedures for reporting suspicious situations,
  • verification of links and senders.

Cybersecurity Training

Ensure the organization's real resilience

The data presented in this article is not statistics from overseas. It pertains to the everyday reality of Polish companies, local governments, and institutions. Most cyberattacks begin with a click on a fraudulent link, attachment, or SMS message. It only takes one unaware employee to expose the entire organization to serious consequences.

Therefore, building resilience starts with people

At ODO 24, we assist companies and institutions not only in identifying threats but, above all, in preparing the team to fend them off. In our offer, you will find:

A well-prepared team is the best protection against an attack – before it occurs.


Test yourself – take the quiz

 

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.