Poland said a cyberattack compromised the private email accounts of senior officials, ministers, members of parliament, and journalists, with stolen messages later leaked on Telegram. Authorities said the campaign affected more than 30 people, included the mailbox and social media compromise of Prime Minister’s Office chief Michał Dworczyk and his wife, and was assessed by Poland’s Internal Security Agency, Military Counterintelligence Service, and allied intelligence services as having been conducted from infrastructure in the Russian Federation.
Polish officials described the operation as a broad attempt to destabilize the country, while investigators preserved evidence and notified affected individuals with guidance to secure their accounts. Separate reporting from CERT Polska and SKW tied ongoing Russian espionage activity against NATO and EU diplomatic targets to infrastructure, techniques, and tooling overlapping with NOBELIUM/APT29, including spear-phishing, malicious links, HTML Smuggling, deceptive shortcut files, hidden DLL execution, and DLL sideloading, reinforcing the assessment that the breach fit a wider Russian intelligence collection campaign.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Polish authorities said police officers would start contacting affected and potentially affected individuals that day to inform them about the incident and provide guidance on securing their email accounts. This notification effort accompanied the ongoing investigation.
Deputy Prime Minister Jarosław Kaczyński said leading Polish officials, ministers, and MPs from different parties had been targeted in a broad cyberattack assessed by Polish and allied services as conducted from the territory of the Russian Federation. Authorities said investigative and evidence-preservation actions were underway.
On June 9, Michał Dworczyk, head of the Polish Prime Minister’s Office, said unknown attackers had breached his email account, his wife's mailbox, and their social media accounts. He said Polish state services had been informed and that the compromised mailbox was not used to send information threatening state security.
On the Friday before the report, Poland handed a document describing recent cyberattacks to EU member states, the European Commission, and the Council. An EU diplomat said Polish national cybersecurity incident response teams had linked the infrastructure and modus operandi to Russian-sponsored entities.
Attacks targeting Polish MPs, government officials, and journalists began in September of the previous year, according to reporting cited in the source. The campaign ultimately affected more than 30 people and involved theft of emails later leaked online.
CERT Polska and Poland's Military Counterintelligence Service published a report on an ongoing espionage campaign linked to Russian special services targeting foreign ministries and diplomatic missions, mainly in NATO and EU countries. They said the activity overlapped with NOBELIUM/APT29 but also used previously undocumented malware and tooling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcegov.pl
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.