Polska Agencja Kosmiczna
Incident posture
Linked entities
- Victim
- Polska Agencja Kosmiczna
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Polish cybersecurity services detected unauthorized access to the Polish Space Agency's IT infrastructure, prompting immediate action to secure affected systems and disconnect the agency's network from the Internet to protect data. The Digitalisation Minister confirmed the incident on social media, noting that intensive operational activities are underway to identify the responsible actor. The agency verified the cybersecurity incident and stated that the situation is being actively analysed. While Warsaw has previously accused Moscow of attempting to destabilise Poland due to its military aid to Ukraine, no attribution was officially made in connection with this attack.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 2, 2025, Polish cybersecurity authorities identified unauthorized access to the information technology infrastructure of the Polish Space Agency (POLSA), prompting an immediate operational response and the public disclosure of the intrusion by senior government officials. Krzysztof Gawkowski, Poland's Minister for Digitalisation, announced the cyberattack on the social media platform X, stating that the systems affected by the incident had been secured and that intensive operational activities were already in progress to identify the party responsible for the intrusion. Gawkowski's statement on Sunday marked the first public confirmation of the breach and signalled the start of a coordinated national-level investigation into the incident. The agency's own communication to the Polish Press Agency (PAP) corroborated the official account, confirming that a cybersecurity incident had taken place and that POLSA personnel were analysing the situation to determine its full scope.
Upon detection of the unauthorized access, POLSA took the immediate protective step of disconnecting its network from the Internet in order to secure agency data and prevent further intrusion. According to the statement provided by the agency to PAP, the decision to sever external connectivity was made as a precautionary measure to preserve the integrity of agency information while the incident was being assessed. The agency's network disconnection was undertaken at the same time that the broader cybersecurity services of the Polish state were engaged in identifying the source of the attack, reflecting a parallel technical and investigative response to the breach.
The incident occurred against a wider backdrop of Polish government allegations that Russia has been attempting to destabilise Poland, accusations that have been linked by Warsaw to the country's role as a supplier of military aid to neighbouring Ukraine. The Reuters report noted that Poland has repeatedly accused Moscow of attempting to destabilise the country for this reason, and that Russia has rejected such allegations. The Reuters article did not, however, attribute the POLSA cyberattack to any specific actor, nor did it confirm that a state-sponsored threat was responsible for the intrusion. The only public linkage between the cyberattack and the broader geopolitical context was the placement of the story within this ongoing diplomatic dispute, with the source material limiting itself to the statement that authorities were working to identify who was behind the cyberattack.
Following the detection and initial containment of the breach, Polish cybersecurity services began the process of analysing the incident to determine how the unauthorized access had been obtained and what, if any, data or systems had been compromised. The statement from Minister Gawkowski confirmed that operational activities were underway aimed at identifying the perpetrator, indicating that attribution was an active component of the post-incident work being conducted by relevant authorities. No further details about the specific systems affected, the method of intrusion, the duration of unauthorised access prior to detection, or the potential exfiltration of data were disclosed in the Reuters report or in the information that POLSA shared with PAP at the time of the announcement. The agency's communications focused on confirming the occurrence of the incident, the securing of affected systems, the disconnection of its network from the Internet, and the ongoing analysis of the situation.
The reporting on the incident, provided by Anna Wlodarczak-Semczuk and edited by David Holmes for Reuters, marked the first stage of public disclosure, with the article appearing on March 2, 2025, and drawing on information released by both Minister Gawkowski and POLSA via PAP. As of that reporting, the Polish government and the agency itself had not released additional technical details regarding the nature of the intrusion, the identity of any threat actor, or the full scope of the potential impact on POLSA's information technology environment. The incident remained under active analysis by Polish cybersecurity authorities, with the agency continuing to operate with its network disconnected from the Internet while the investigation proceeded.
Sources
Sources available to members: 1 source.