The CERT Polska 2025 report clearly shows that computer fraud dominates in Poland today, and its most common form remains phishing. For CISOs and security teams, this is a clear signal that educational programs should focus on practical preparation of employees to recognize and report such attacks – for example, using personalized phishing simulations. Especially since phishing messages are increasingly unlikely to resemble a primitive attempt at fraud. On the contrary – they do not have typical errors, are more credible and well suited to the context and role of the recipient.
The schemes most frequently described by CERT Polska include campaigns impersonating tax refunds, undelivered parcels, correspondence from websites in the gov.pl domain, social benefits and e-TOLL fees. The report also shows that many of these campaigns were multi-step, combining email or text messages with time pressure, a fake phishing site, or an attempt to trick the victim into making a phone call and installing malware.
There is no doubt that artificial intelligence is driving increasingly sophisticated cyberattacks. We showed how cybercriminals use AI to scale, authenticate and automate attacks during our free AI vs Cybersecurity webinar series. The series has ended, but access to the recordings and materials is still available here.
A series of AI vs Cybersecurity webinars for CISOs
How does AI affect cyber threats and how to use artificial intelligence as an element of a security strategy?
Social engineering attacks in Poland – key statistics from the CERT Polska 2025 report
- 260,783 – this is how many unique security incidents were registered by CERT Polska in 2025.
- 253,238 – this is how many of them were classified as computer fraud, i.e. 97% of all incidents handled.
- 78,391 – so many incidents concerned phishing attacks, which accounted for 30% of all recorded events.
- Almost 245 thousand – this is how many domains were added to the CERT Polska Warning List in 2025.
- 141.1 million – this is how many entries to dangerous websites were blocked by the Warning List.
- 295,169 – this is how many reports of suspicious SMS messages the CERT Polska team received.
- 1,883,610 – this is how many malicious SMS messages the operators blocked based on patterns published in this system.
What is CERT Polska and what does it do?
CERT Polska is the country’s first cybersecurity incident response team. It has been operating within NASK structures since 1996, and in 2026 it will celebrate its 30th anniversary. This team has been monitoring threats on the Polish Internet for years, handling reports and publishing reports that clearly show what the incident landscape in Poland really looks like.
In practice, CERT Polska deals primarily with:
- monitoring threats and incidents at the national level,
- reacting to reported incidents and coordinating their handling,
- malware and vulnerability analysis,
- developing tools and methods for detecting threats,
- building awareness in cybersecurity.
CERT Polska also carries out some of the tasks of CSIRT NASK in accordance with the Act on the national cybersecurity system (KSC). It handles incidents reported by public institutions, digital service providers, companies and individuals.
Phishing and computer fraud – statistics of cyber threats in Poland in 2025
Size of the problem: computer fraud was the main category of security incidents
In 2025, computer fraud dominated the landscape of incidents in Poland. The CERT Polska team registered260,783 security incidents, and 253,238 of them were classified as computer fraud. This means 97% of all events handled. CERT itself also recorded growth in this category by 158% year-on-year, which clearly shows that we are not talking about a temporary jump, but about a lasting trend.
Number of phishing attacks in 2025
Phishing was the most frequently recorded type of computer fraud. According to CERT Polska‘s report, 78,391 phishing incidents were recorded in 2025. This is 30% of all registered events, which shows that phishing remains one of the most important mechanisms used by cybercriminals to extort confidential data and, in many scenarios, also to gain access to victims’ money.
What brands and scenarios were most often used in phishing campaigns?
The more recognizable the website and the more natural the context of the message, the greater the chance that the user will react without thorough verification. The most frequently observed phishing campaigns concerned unauthorized use of the image of OLX – 28,462 events and Allegro – 22,513 events. Attempts to obtain credentials for electronic mailboxes also constituted a separate category – 2,519 events.
Smishing still an important fraud channel
SMS remains an important channel used in social engineering fraud in 2025. The CERT Polska team received 295,169 reports of suspicious SMS messages, and the report indicates that most visits to phishing websites occur within 15 minutes of receiving the message. This shows how strongly this type of campaigns use the speed of reaction and impulsive actions of recipients.
The number of blocks shows that phishing was operating on a massive scale
In 2025, almost 245,000 were added to the CERT Polska Warning List. domains. The report also indicates that the list was downloaded almost 1.3 billion times, as a result, approximately 141.1 million visits to dangerous websites were blocked. Additionally, in the SMS area, 790 patterns led to blocking of 1,883,610 malicious messages.
Data from the CERT Polska report show that organizations should treat resistance to social engineering as a permanent element of their security strategy, not a one-off educational campaign. Technological security alone is not enough. Organizations needregular phishing teststhat show employees’ actual vulnerability to cyberattacks, and asimple process for reporting suspicious messagesthat speeds up the response and helps block the threat. This is especially important in the environment of increasingly greater legal and regulatory requirements, such as the AI Act, KSC 2.0, GDPR, DORA or NIS2.
At SECAWA, we have provided these needs in one service – Practical Anti-Phishing Training, which combines education in a controlled environment, measurable results for the management board or auditors and convenient incident reporting. It is an original platform for simulating cyberattacks (including phishing, smishing, quishing, and soon also Microsoft Teams simulations and vishing integrated with AI) fully operated by our team. As a result, Polish organizations can strengthen their cybersecurity resilience without burdening resources, but also meet regulatory requirements such as AI Act, KSC 2.0, GDPR, DORA or NIS2 for security awareness.
Learn about your team’s resistance to phishing and see how our cyberattack simulation platform works – without costs or obligations!
The most frequently observed social engineering campaigns in Poland in 2025
According to the CERT Polska report, fraudsters most often used in 2025 scenarios based on trust in well-known institutions and everyday services. Campaigns aimed at taking over passwords to email boxes and social media accounts, as well as fake websites pretending to be state services and courier companies, especially Poczta Polska and InPost, were particularly common.
Tax refund: e-Tax Office and KAS
The fraudsters sent messages about an alleged refund awaiting approval, using the image of the Ministry of Finance and the style of official correspondence. The goal was not just to click, but to guide the victim through the entire extortion process – from entering a crafted website to providing electronic banking and payment card details.
Undelivered parcels: InPost, Poczta Polska, e-Delivery
A classic example of a campaign that works because it fits well into the user’s everyday context. CERT Polska describes both email messages with attachments installing malware and SMS messages directing to fake websites used to extort personal data and payment card details. Importantly, the report also draws attention to variants that bypass the phone’s security – e.g. by persuading the user to reply to a message, which makes it easier to activate the link.
Official matters: services in the gov.pl domain
Fraudsters sent messages about new official correspondence, account activity or logging in from an unknown device. In this scenario, the message was often just the first step. The next step was to persuade the recipient to contact him by phone and then – during the conversation – convince him to install a tool enabling remote access to the computer (vishing).
Verification of entitlement to social benefits
A pattern in which an advertisement or message directed the user to a false website stylized as gov.pl, and then to a form impersonating a payment operator. This example shows that a cyber attack does not have to start with an email – it can equally effectively use advertising, a simple form and a financial context that is natural to the user.
e-TOLL fee
In 2025, CERT also observed campaigns using the motif of unpaid toll. This scenario was based on time pressure and the risk of financial consequences. The attack was two-stage: first, personal data was extorted, including ID number, and then payment card details.
Statistical Office and malicious attachment
The CERT Polska report also describes campaigns impersonating the Statistical Office in Warsaw. In this case,social engineering was a carrier for malware. The message looked legitimate, contained formal content and a detailed footer, and the attachment led to the launch of RAT-type software. This could result in both stealing saved passwords and taking control of the victim’s device.
False investments in social media
One of the most financially painful scenarios was investment fraud. Fraudsters registered fake investment websites en masse and often used the images of public figures or well-known brands. The mechanism was not based solely on the promise of profit. Falsified charts, time pressure and the victim’s belief that they were dealing with a limited opportunity with minimal risk also played a role.
NFZ and reimbursement of drug purchase costs
The criminals impersonated the National Health Fund and informed about the possibility of recovering the costs of purchasing medicines. The user was directed to a website used to steal personal data and passwords. There is an important psychological element here: short deadlines for receiving funds, which were intended to limit the time for reflection and verification of the message.
Refund of overpayment for electricity
The report also describes campaigns impersonating electricity suppliers. Their effectiveness resulted from the combination of a current topic – energy costs – with a very refined form. The messages were written in correct Polish, maintained a formal style and faithfully reproduced the appearance of legal websites of energy operators. The conclusion is simple: modern phishing, which is often supported by AI, is no longer revealed by simple linguistic errors.
What do these social engineering campaigns have in common?
Although they differ in subject matter, their mechanism usually remains similar: first build credibility, then add time pressure and embed the message in a situation that will seem familiar to the recipient. The authority of institutions or services present in users’ everyday lives was particularly often used because it increases the chance of clicking, providing data or performing other risky actions.
Therefore, organizations should regularlypractice safe responses to scenarios based on real threats from the Polish Internet. As part of Practical Anti-Phishing Training, we prepare campaigns tailored to the specificity of a given company, processes, tools used, positions and industry, so that our phishing simulations best replicate attacks that may be aimed at employees.
Practical Anti-Phishing Training: realistic simulations of cyberattacks, measurable training effects and ready-made reports for the management board and auditors
Security incidents in Poland in 2025
The most important incidents described in the CERT Polska 2025 report show that an effective attack is less and less based on one channel and one user error. Increasingly, we are seeing the entire chain of activities: phishing, account takeover, use of legal login mechanisms, extortion of data about specific people or further use of leaked data.
For CISOs, this means that the organization must simultaneously practice recognizing suspicious messages, build resistance to multi-stage and multi-channel attacks, and provide the team with clear response procedures that will allow the incident to be stopped before it develops further.
Selected incidents described in the CERT Polska 2025 report
- UNC1151 and mailbox campaigns
CERT Polska described campaigns conducted over many weeks, targeting hundreds of people using email on the Interia, Onet and Wirtualna Polska websites. The attackers used not only their own domains, but also hijacked websites belonging to Polish entities to increase the credibility of the attack. - Roundcube – phishing combined with a vulnerability
In campaigns against Polish entities, a vulnerability in Roundcube was used to steal credentials – the example shows that phishing can only be the beginning, and the actual attack develops further by technically taking over access. - Device Code Phishing and Microsoft 365
The attackers impersonated an employee of the Polish Ministry of Foreign Affairs and tried to gain access to Microsoft 365 resources belonging to employees of European embassies. The mechanism did not involve a classic false login and password, but rather an abuse of the legal authentication process using a generated code. - Phishing of data about people responsible for security
CSIRT NASK observed a campaign impersonating the Ministry of Digitization and Deputy Minister Paweł Olszewski. In one of the variants, the aim was to extort contact details of people responsible for IT security in local government units in order to later conduct more precise directional attacks. - Hijacked Facebook accounts and extorting BLIK codes. The report also describes the case of a group that first obtained Facebook logins by phishing and then extorted BLIK codes from subsequent people via messenger. Over 100,000 were secured. stolen logins and passwords. This clearly illustrates how one compromised account can trigger a further chain of fraud.
- Data leaks as a starting point for further frauds
Data obtained by criminals can later be used to authenticate future social engineering attacks. This means that the leak does not close the incident – it often only increases the effectiveness of subsequent phishing campaigns and attempts to impersonate trusted entities.
Summary
The CERT Polska 2025 report very clearly shows the scale of phishing attacks in Poland – their number and level of refinement. The report covers more than phishing; it also includes a broader picture of threats: from mobile malware and ransomware to the activities of APT groups.
Importantly, CERT Polska does not limit itself to describing the problem, but actively helps to limit it – through the Warning List, blocking malicious SMS messages, the moje.cert.pl portal, the bezpiecznedane.gov.pl, number 8080 for reporting suspicious messages and current messages about campaigns and vulnerabilities.