Key facts
- Over 10,000 Polish public entities and 250,000 websites were found to be at risk of hacking.
Security researchers discovered over 10,000 public entities in Poland, including courts, hospitals, and airports, are vulnerable to cyberattacks due to outdated software and poor security reporting mechanisms. The findings highlight significant risks to public services.

The widespread vulnerabilities in Poland's public sector infrastructure expose critical services like hospitals and airports to potential cyberattacks, posing risks to national security and public safety. The findings underscore the urgent need for improved cybersecurity practices and vendor accountability in protecting essential public services.
Polish security researchers Robert Kruczek and Kamil Szczurowski have uncovered significant cybersecurity risks across Poland's public sector, identifying over 10,000 public entities and 250,000 websites vulnerable to hacking. The findings, presented at the Def Con cybersecurity conference, highlight issues stemming from outdated software, such as the Pad CMS, and a lack of robust mechanisms for reporting and addressing security flaws.
The researchers discovered critical vulnerabilities that allowed them to access hundreds of public websites without passwords, including those of airports, hospitals, and government offices. Notably, approximately two-thirds of Poland's judiciary, comprising about 245 courts, were found to be affected by these security weaknesses.
Kruczek and Szczurowski noted that some vendors dismissed bug reports as inconveniences, exacerbating the risk of hijacks and other cyberattacks. This research emerges at a critical time for Poland, which has been bolstering its cyber defenses following a series of suspected Russian-linked hacks targeting its energy and water infrastructure.
The duo reported their findings through official government channels, expressing hope that their work contributes to making the country's digital infrastructure safer.