News
Cyberattacks in Poland Rose 152 Percent as AI Becomes Hackers' Main Tool

An updated Polish government report shows security incidents handled by CSIRT NASK jumped 152 percent in 2025, and NASK's director warns that artificial intelligence is cutting the time responders have to react.
A government cybersecurity report updated this week shows a scale of attacks that Poland's national incident response teams have never recorded before. The number of confirmed attacks rose by more than 140 percent in 2025, and Deputy Prime Minister Krzysztof Gawkowski and NASK director Radosław Nielek both point to artificial intelligence as the key factor driving the surge.
The data comes from the report of the Government Plenipotentiary for Cybersecurity and the Ministry of Digital Affairs, originally published in April and updated on September 8. The document describes 2025 as the moment cyberspace became one of the key areas of state security, with the threat landscape dominated by the professionalization of cybercrime and the activity of APT groups linked to Russian and Belarusian intelligence services.
Numbers that raise alarm
CERT Polska, which operates within NASK, received 682,250 breach reports in 2025, about 10 percent more than the year before. But the number of cases that turned out, after verification, to be real incidents grew far more sharply. Separately reporting teams CSIRT MON and CSIRT GOV logged 7,125 incidents (up 69 percent) and 5,033 incidents (up 26.1 percent), respectively.
The most telling figure, though, is the rise in attack success rate. In 2024, fewer than 17 percent of reports turned into a confirmed security incident. In 2025, that share climbed to nearly 40 percent, meaning attackers now hit their mark almost twice as often as just a year earlier.
AI as a criminal tool
The report's authors state plainly that artificial intelligence has become the key attack vector, enabling mass automation of social engineering campaigns. Instead of single, carefully crafted spear phishing attacks aimed at select individuals, criminals can now generate thousands of personalized messages tailored to specific recipients at almost no extra cost.
The key attack vector has become the use of artificial intelligence, which has enabled, among other things, the mass automation of social engineering campaigns - Krzysztof Gawkowski, Deputy Prime Minister and Minister of Digital Affairs
NASK director Radosław Nielek, who has repeatedly warned about this trend in recent months, stresses that the problem isn't just the number of attacks but the speed at which responders must react. He notes that spear phishing attacks used to target individuals who were especially valuable to criminals, but thanks to AI, that same level of personalization is now available to target virtually any internet user.
AI has certainly changed this world too, because of AI we have less time to intervene - Radosław Nielek, NASK director
NASK's response
In response to the growing scale of threats, NASK is building a Cybersecurity Center, an investment worth more than 350 million zlotys, due to be completed by 2030. It will include new vulnerability detection technologies, AI security labs, and training centers for government administration and experts.
But Nielek says the biggest challenge isn't hardware, it's people. In his view, it's better to spend twice as much on skilled staff than twice as much on infrastructure, since it's the shortage of qualified personnel, not a lack of technology, that limits Poland's ability to fend off attacks today.
What it means for Poland
The report confirms what experts have been saying for months: Poland is one of the most frequently attacked countries in Europe, and attack targets have long since expanded beyond government and military institutions. Victims today also include small businesses, hospitals, schools, and ordinary citizens, whose login credentials or email accounts have become commodities for criminals.
For companies and public institutions, this means the coming months will require not only investment in technical safeguards but also preparing employees for increasingly convincing, personalized scam attempts. Since the cost of preparing such an attack has dropped to nearly zero, the number of attempts in the coming quarters is likely to keep rising rather than level off.


