Poland detains Russian citizen suspected of hacking local firms

Polish authorities detained a Russian citizen suspected of hacking into the IT systems of local companies — the latest in a series of cases Warsaw has linked to Moscow’s expanding sabotage and espionage efforts.

Interior Minister Marcin Kierwiński said Thursday that police arrested the man for breaching security systems to gain access to company databases. A more detailed statement from the Krakow prosecutor’s office said the suspect allegedly hacked into an online retailer’s systems without authorization and manipulated its databases in ways that could have disrupted operations and endangered customers.

The suspect, whose identity has not been disclosed, illegally crossed into Poland in 2022 and obtained refugee status the following year. He has been placed in temporary custody while the investigation continues.

Authorities believe the man may be linked to additional cybercriminal activity targeting companies in Poland and across the EU, and are still assessing the scale of the possible damage.

Poland has repeatedly warned of heightened Russian intelligence activity since Moscow’s full-scale invasion of Ukraine. Prime Minister Donald Tusk said in July that 32 people — including Polish, Russian, Ukrainian, Belarusian and Colombian nationals — had been detained on suspicion of working with Russian services to carry out sabotage and arson attacks.

Earlier this year, Warsaw closed the Russian consulate in Krakow after linking Moscow’s intelligence services to a 2023 fire that destroyed a major shopping mall in Warsaw. Last week, Poland shut down the last remaining Russian consulate in the country after authorities said Russian intelligence was suspected of involvement in an explosion on a Polish railway line, which officials described as an act of sabotage.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan

Next Post

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

Related Posts

Cisco Patches Zero-Day RCE Exploited by China-Linked APT in Secure Email Gateways

Cisco on Thursday released security updates for a maximum-severity security flaw impacting Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, nearly a month after the company disclosed that it had been exploited as a zero-day by a China-nexus advanced persistent threat (APT) actor codenamed UAT-9686. The vulnerability, tracked as CVE-2025-20393 (CVSS
Read More

Google Launches New Maps Feature to Help Businesses Report Review-Based Extortion Attempts

Google on Thursday said it's rolling out a dedicated form to allow businesses listed on Google Maps to report extortion attempts made by threat actors who post inauthentic bad reviews on the platform and demand ransoms to remove the negative comments. The approach is designed to tackle a common practice called review bombing, where online users intentionally post negative user reviews in an
Read More