Poland’s National Centre for Nuclear Research (NCBJ) said hackers targeted its IT infrastructure, but the intrusion was detected and blocked before systems were compromised. The institute said the MARIA research reactor continued operating safely and was not affected, while Polish authorities opened an investigation and placed internal security teams on heightened alert. Reporting cited by one source said investigators found indicators that Iran may be behind the operation, although officials cautioned those signs could also be a false flag.
Albania’s parliament also reported a sophisticated cyberattack aimed at deleting data and compromising internal systems, temporarily disrupting parliamentary email services while leaving the main website and core systems operational. A group known as Homeland Justice claimed responsibility and published alleged screenshots of stolen parliamentary communications, though Albanian authorities had not verified the claims at the time of reporting. Homeland Justice has previously been linked by researchers and Western officials to Iran’s IRGC, but the two incidents remain separate events with different targets, attribution status, and operational details; broader discussion of Salt Typhoon and U.S. telecom policy is unrelated to these attacks.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
As the investigation progressed, Polish officials said early indicators pointed to possible activity originating from Iranian infrastructure. Authorities cautioned that the signs could be false flags and said no public technical evidence had been released to support firm attribution.
Following the attempted breach, NCBJ notified relevant authorities and began a coordinated response with national cybersecurity and government agencies. The institute raised its internal security alert level and started analyzing the incident to strengthen defenses.
On March 12-13, Poland’s National Centre for Nuclear Research detected and blocked a cyberattack targeting its IT infrastructure before any compromise or operational disruption occurred. NCBJ said the MARIA research reactor continued operating safely at full power throughout the incident.
The hacker group Homeland Justice claimed it carried out the attack on Albania’s parliament and said it had obtained internal communications, posting screenshots of purported leaked documents on Telegram. Albanian authorities did not verify the claim and said cybersecurity agencies were investigating.
Albania’s parliament reported a sophisticated cyberattack aimed at deleting data and compromising internal systems. Internal email services for the parliamentary administration were temporarily suspended, leaving staff and lawmakers unable to access computers and email for several hours, while the main systems and website remained operational.
Before the latest incident, the Iran-linked group Homeland Justice had publicly claimed attacks on Albanian targets including parliament, the national airline, telecom firms, and the national statistics agency. These earlier operations form the backdrop to the new claim against Albania’s parliament.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourcencbj.gov.pl
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.