Platforma Obywatelska
Incident posture
Linked entities
- Victim
- Platforma Obywatelska
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Poland's ruling political party suffered a cyberattack on its IT systems, prompting Prime Minister Donald Tusk to allege foreign interference in upcoming elections. The Digital Affairs Minister confirmed the incident was serious and that national security services were working intensively to address it, with the head of Tusk's office stating that analysis indicated the method of operation associated with Eastern services, suggesting Russian or Belarusian involvement. The attack reportedly involved unknown actors compromising a local party activist's account to distribute emails containing malicious software, including one sent to a parliamentary address. The incident occurred amid heightened concerns over foreign sabotage targeting Poland's role in supporting Ukraine, following previous cyberattacks on the Polish state news agency and space agency.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On April 2, 2025, Polish Prime Minister Donald Tusk announced that the IT systems of his political party, Civic Platform (Platforma Obywatelska), had been targeted by a cyberattack. Tusk disclosed the incident in a post on the social media platform X, stating, "Cyberattack on (Civic) Platform's IT system," and adding, "Foreign interference in elections begins. Services point to an eastern trace." He did not provide further details in his public statement. The disclosure came amid heightened concerns in Warsaw regarding foreign interference and sabotage ahead of a presidential election scheduled for May 2025. Polish officials have previously stated that the country's support for Ukraine makes it a key target for Russian security services, a claim that Moscow has dismissed.
Digital Affairs Minister Krzysztof Gawkowski confirmed the severity of the incident on X, noting that security services were working intensively on the matter. According to state news agency PAP, Jan Grabiec, the head of Tusk's office, stated that services analyzing the attack had identified "specific data indicating the method of operation of the services from the East." When asked by PAP whether he was referring to Russian or Belarusian services, Grabiec said he did not want to speak on behalf of the Polish security services but noted that "very often (Eastern) services infiltrate on behalf of the Russian services - Belarusians act or Belarusian data is also used to mask."
Further details about the method of the attack emerged through a journalist from the private broadcaster Radio Zet, who reported on X that unknown actors had taken over the account of a local Civic Platform activist. From this compromised account, the attackers distributed emails containing malicious software. At least one of these malicious emails was sent to a parliamentary account. The incident was contextualized by opposition lawmaker and former deputy minister of justice Michal Wos, who told Radio Zet that "This is clearly Donald Tusk's prelude to the Romanian or French scenario, they are preparing for the presidential elections."
The cyberattack on Civic Platform was not an isolated event in Poland's broader cybersecurity landscape. In January 2025, Digital Affairs Minister Gawkowski had stated that Poland had identified a Russian group tasked with influencing the Polish elections through disinformation and the stoking of instability. In March 2025, Warsaw reported a separate cyberattack targeting the Polish space agency. Additionally, in 2024, Poland indicated that the state news agency had likely been hit by a Russian cyberattack. Warsaw and its allies have also accused Moscow of being behind various acts of arson and sabotage across Europe, allegations that Russia continues to deny.
Sources
Sources available to members: 1 source.