Poland detains Russian citizen suspected of hacking local firms

Polish authorities detained a Russian citizen suspected of hacking into the IT systems of local companies — the latest in a series of cases Warsaw has linked to Moscow’s expanding sabotage and espionage efforts.

Interior Minister Marcin Kierwiński said Thursday that police arrested the man for breaching security systems to gain access to company databases. A more detailed statement from the Krakow prosecutor’s office said the suspect allegedly hacked into an online retailer’s systems without authorization and manipulated its databases in ways that could have disrupted operations and endangered customers.

The suspect, whose identity has not been disclosed, illegally crossed into Poland in 2022 and obtained refugee status the following year. He has been placed in temporary custody while the investigation continues.

Authorities believe the man may be linked to additional cybercriminal activity targeting companies in Poland and across the EU, and are still assessing the scale of the possible damage.

Poland has repeatedly warned of heightened Russian intelligence activity since Moscow’s full-scale invasion of Ukraine. Prime Minister Donald Tusk said in July that 32 people — including Polish, Russian, Ukrainian, Belarusian and Colombian nationals — had been detained on suspicion of working with Russian services to carry out sabotage and arson attacks.

Earlier this year, Warsaw closed the Russian consulate in Krakow after linking Moscow’s intelligence services to a 2023 fire that destroyed a major shopping mall in Warsaw. Last week, Poland shut down the last remaining Russian consulate in the country after authorities said Russian intelligence was suspected of involvement in an explosion on a Polish railway line, which officials described as an act of sabotage.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Bloody Wolf Expands Java-based NetSupport RAT Attacks in Kyrgyzstan and Uzbekistan

Next Post

MS Teams Guest Access Can Remove Defender Protection When Users Join External Tenants

Related Posts

New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps

A rapidly evolving Android spyware campaign called ClayRat has targeted users in Russia using a mix of Telegram channels and lookalike phishing websites by impersonating popular apps like WhatsApp, Google Photos, TikTok, and YouTube as lures to install them. "Once active, the spyware can exfiltrate SMS messages, call logs, notifications, and device information; taking photos with the front
Read More

10 npm Packages Caught Stealing Developer Credentials on Windows, macOS, and Linux

Cybersecurity researchers have discovered a set of 10 malicious npm packages that are designed to deliver an information stealer targeting Windows, Linux, and macOS systems. "The malware uses four layers of obfuscation to hide its payload, displays a fake CAPTCHA to appear legitimate, fingerprints victims by IP address, and downloads a 24MB PyInstaller-packaged information stealer that harvests
Read More

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

A recently disclosed security flaw impacting 7-Zip has come under active exploitation in the wild, according to an advisory issued by the U.K. NHS England Digital on Tuesday. The vulnerability in question is CVE-2025-11001 (CVSS score: 7.0), which allows remote attackers to execute arbitrary code. It has been addressed in 7-Zip version 25.00 released in July 2025. "The specific flaw exists
Read More