Cyberataki na polskie firmy

Poniższa lista pokazuje realne ataki i wycieki danych dotykające polskich firm — kontekst dla checklisty bezpieczeństwa: to się dzieje naprawdę. Zobacz, jak się zabezpieczyć.

08.2026

LOG Systems
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 21.08.2026 · Wykryto: 21.08.2026 08:29 UTC

logsystem.pl zoominfo.com/c/log-systems/372786485 LOG Systems is a Polish software company based in Wrocław that develops comprehensive IT management and Helpdesk solutions. Their flagship product, LOG Plus, is an advanced ITSM platform designed to…

Źródło: ransomware.live
GB Group S.A
Financial ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 11.08.2026 · Wykryto: 13.08.2026 14:23 UTC

GB Group is one of Haiti’s largest private industrial and trading conglomerates. Headquartered in Port-au-Prince, it operates across nine core industries including construction materials, consumer goods, and energy. Recently, the organization…

Źródło: ransomware.live
Ponti
OtherRansomware⚠ niepotwierdzone

Szacowana data ataku: 06.08.2026 · Wykryto: 07.08.2026 08:07 UTC

ponti.pl Ponti is a specialized automotive company based in Gdańsk, Poland, focused on the direct import, sales, and professional servicing of American vehicles. Operating as a leading expert in the US car market, the company handles everything from…

Źródło: ransomware.live
Mera Metal
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 05.08.2026 · Wykryto: 05.08.2026 18:29 UTC

N/A

Źródło: ransomware.live

07.2026

Paula Fish
OtherRansomware⚠ niepotwierdzone

Szacowana data ataku: 31.07.2026 · Wykryto: 31.07.2026 18:23 UTC

paulafish.pl zoominfo.com/c/paula-fish/448451882 Paula Fish is a market leader in fish processing in Central Europe, headquartered in Słupsk, Poland. Founded in 1998, the company specializes in the catching, production, freezing, and storage of…

Źródło: ransomware.live
Bater
OtherRansomware⚠ niepotwierdzone

Szacowana data ataku: 31.07.2026 · Wykryto: 31.07.2026 18:26 UTC

bater.pl zoominfo.com/c/bater-ltd/429692403 Bater is a leading Polish manufacturer of traction and stationary batteries, founded in 1990 with production facilities in Warsaw and Gliwice. The company specializes in producing high-quality battery…

Źródło: ransomware.live
BioResearch
HealthcareRansomware⚠ niepotwierdzone

Szacowana data ataku: 25.07.2026 · Wykryto: 25.07.2026 17:55 UTC

BioResearch Group to Warsaw clinical research center specializing in early phases (I, FIH, SAD, MAD) and bioequivalence studiesThe company offers comprehensive services for the pharmaceutical and CRO sectors, with its own clinic and laboratory.

Źródło: ransomware.live
Raben Group
TransportationRansomware⚠ niepotwierdzone

Szacowana data ataku: 23.07.2026 · Wykryto: 23.07.2026 15:09 UTC

***.com zoominfo.com/c/raben-group/350966506 Raben Group is a leading European logistics provider with Dutch roots, founded in 1931 and currently headquartered in Poznań, Poland. The company offers comprehensive transport and warehousing solutions,…

Źródło: ransomware.live
Agapit
OtherRansomware⚠ niepotwierdzone

Szacowana data ataku: 23.07.2026 · Wykryto: 23.07.2026 15:10 UTC

***.pl zoominfo.com/c/agapit-sp-z-oo-spk/372573662 Agapit is one of the largest suppliers of professional cleaning technology and equipment in Poland, with over 26 years of experience. The company provides comprehensive solutions, including…

Źródło: ransomware.live
Lsn
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 16.07.2026 · Wykryto: 16.07.2026 12:57 UTC

***.io zoominfo.com/c/lsn/557824732 software development company specializing in tailor-made IT solutions for the insurance industry. Founded in 2008 as Logisfera Nova and rebranded in 2020, the company provides full-stack services including…

Źródło: ransomware.live
EXPRESOKNA SP. Z O.O.
Professional ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.07.2026 · Wykryto: 10.07.2026 12:56 UTC

EXPRESOKNA SP. Z O.O. a Polish manufacturer and distributor specializing in window and door systems. Based in Siemianowice Śląskie, the company is known for its exceptionally fast turnaround times for PVC and aluminum products.

Źródło: ransomware.live
Bär Cargolift Polska Sp. z o.o.
TransportationRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.07.2026 · Wykryto: 10.07.2026 12:56 UTC

Bär Cargolift specializing in the manufacturing of hydraulic tail lifts for vehicles, featuring products with capacities from 500 kg to 3,000 kg. The site offers an online WebShop for spare parts, technical support via Bär CargoCheck, and operator…

Źródło: ransomware.live
SKK Networks Sp. z o.o. and UNICARD Systems Sp. z o. o. and SKK SA
Professional ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.07.2026 · Wykryto: 10.07.2026 12:57 UTC

SKK Networks is a specialized IT infrastructure provider based in Kraków, Poland, that designs, builds, and maintains professional LAN and WLAN networks. They focus on creating high-performance connectivity solutions for challenging environments…

Źródło: ransomware.live
PB Sprinkler Engineering Sp. z o.o. and PLISZKA Fire Protection Engineering
Professional ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.07.2026 · Wykryto: 10.07.2026 12:58 UTC

PB Sprinkler Engineering (formerly Pliszka Sprinkler) provides comprehensive fire protection solutions, including technical design in 2D and 3D, and customized, certified systems. The company specializes in electronic detection and fixed gas…

Źródło: ransomware.live
GEOPARTNER Sp. z o.o. and GEOPARTNER GEOMATICS Sp. z o.o.
Professional ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.07.2026 · Wykryto: 10.07.2026 12:59 UTC

Geopartner Geomatics Sp. z o.o. is a Gdańsk-based engineering firm specializing in advanced surveying, mapping, and BIM services for the infrastructure sector. The company utilizes LiDAR scanners and drones to support road and rail projects,…

Źródło: ransomware.live
LIVISTO
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.07.2026 · Wykryto: 10.07.2026 13:07 UTC

LIVISTO is an international pharmaceutical company with extensive experience in the veterinary market.

Źródło: ransomware.live
wydawnictwowam.pl
Wyciek danych

Data wycieku: 07.2026

W lipcu 2026 roku doszło do nieuprawnionego dostępu do zasobów testowej instancji systemów wydawnictwa WAM (wydawnictwowam.pl). Dane testowe, do których uzyskały dostęp osoby nieupoważnione, stanowią kilka procent danych produkcyjnych z okresu 09.2016 - 08.2021 i obejmują imiona, nazwiska, numery telefonów, adresy e-mail, kody pocztowe oraz nazwy kont zarejestrowane w systemie wydawnictwa. Potwierdzono, że baza danych klientów serwisu została opublikowana do pobrania na jednym z forów dla cyberprzestępców. Incydent objął około 60 tysięcy unikalnych rekordów.

Źródło: bezpiecznedane.gov.pl

06.2026

MakoLab
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 30.06.2026 · Wykryto: 01.07.2026 22:19 UTC

***.com zoominfo.com/c/makolab-sa/31278202 MakoLab, a prominent Polish IT consulting and software development company acting as a digital project house.The firm specializes in digital transformation, artificial intelligence, custom software…

Źródło: ransomware.live
Kozminski University
EducationRansomware⚠ niepotwierdzone

Szacowana data ataku: 15.06.2026 · Wykryto: 15.06.2026 12:57 UTC

***.edu.pl zoominfo.com/c/kozminski-university/372606592 Kozminski University, located in Warsaw, is Poland's premier private business school and a globally recognized academic institution holding the prestigious "Triple Crown" accreditation.…

Źródło: ransomware.live
Techpol-System
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 15.06.2026 · Wykryto: 13.07.2026 12:41 UTC

Techpol-System, based in Bieruń, Poland, is an engineering enterprise specializing in industrial power solutions, including traction battery maintenance, along with laser processing and steel structure fabrication. The company provides…

Źródło: ransomware.live
WCM Remedium
HealthcareRansomware⚠ niepotwierdzone

Szacowana data ataku: 08.06.2026 · Wykryto: 08.06.2026 09:56 UTC

***.pl WCM Remedium (Wielkopolskie Centra Medyczne Remedium) is a private healthcare provider based in Poznań and Śrem, Poland, offering comprehensive medical services to both public insurance (NFZ) and private patients.

Źródło: ransomware.live

05.2026

TRANSSYSTEM Group
TransportationRansomware⚠ niepotwierdzone

Szacowana data ataku: 24.05.2026 · Wykryto: 24.05.2026 09:01 UTC

transsystem.pl Polish engineering powerhouse with 30+ years of expertise in designing and manufacturing advanced technological transport systems and steel structures. Delivers turnkey intralogistics solutions for automotive, tire, and industrial…

Źródło: ransomware.live
tvnmedia.com
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 22.05.2026 · Wykryto: 22.05.2026 09:50 UTC

TVN Media is a multimedia company from Panama, engaged in broadcasting, radio, digital media and ...

Źródło: ransomware.live
RADWAG
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 19.05.2026 · Wykryto: 19.05.2026 13:56 UTC

The website RADWAG.com is the home of RADWAG, a Polish manufacturer widely recognized as a global leader in the production of electronic weighing equipment, including balances, scales, and specialized measuring instruments - Nova Provide tree and…

Źródło: ransomware.live
Wysza Szkoa Biznesu National Louis University
EducationRansomware⚠ niepotwierdzone

Szacowana data ataku: 19.05.2026 · Wykryto: 19.05.2026 18:33 UTC

Wyższa Szkoła Biznesu (WSB-NLU) in Nowy Sącz offers a variety of educational programs including bachelor's, engineering, and master's degrees, as well as postgraduate studies available in RealTime Online format. The institution emphasizes practical…

Źródło: ransomware.live
Digiprint
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 14.05.2026 · Wykryto: 15.05.2026 10:52 UTC

digiprint.pl zoominfo.com/c/digiprint/372856266 leading Polish company established in 2000 that delivers innovative solutions for the printing industry. They specialize in digital and flexographic printing technologies, wide-format production, and…

Źródło: ransomware.live
DEVCO
Professional ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 08.05.2026 · Wykryto: 09.05.2026 09:16 UTC

devco.pl DEVCO Sp. z o.o. is a Polish real estate company established in 1997, headquartered in Wroclaw at ul. Strzegomska 46-56. The company specializes in renting office and warehouse spaces, notably operating the Wroclawski Park Biznesu (Wroclaw…

Źródło: ransomware.live
arbiko.pl
Wyciek danych

Data wycieku: 05.2026

W maju 2026 roku ujawniono informację o wycieku danych pochodzących ze strony internetowej arbiko.pl. Potwierdzono, że baza danych klientów tego serwisu została opublikowana do pobrania na jednym z forów dla cyberprzestępców. Incydent objął ponad 4 tysiące unikalnych rekordów. Dane znajdujące się w wykradzionej bazie obejmują adresy e-mail, hasła przechowywane w postaci jawnego tekstu oraz niekiedy numery telefonów. Ze względu na fakt, że hasła nie zostały poddane procesowi hashowania, istnieje bezpośrednie ryzyko przeprowadzenia ataków polegających na przejęciu kont, w przypadku wykorzystywania tej samej kombinacji adresów e-mail i haseł w innych serwisach. Ponadto, biorąc pod uwagę profil działalności firmy ARBIKO, wykradzione dane kontaktowe mogą zostać wykorzystane do ukierunkowanych ataków socjotechnicznych na przedsiębiorstwa, takich jak fałszywe oferty sprzedaży czy oszustwa fakturowe.

Źródło: bezpiecznedane.gov.pl

04.2026

Raich Sp. z o.o.
Professional ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 27.04.2026 · Wykryto: 27.04.2026 15:34 UTC

Raich Sp. z o.o. is an enterprise in Poland, with the main office in Warsaw. The company operates in the Wired Telecommunications Carriers industry.

Źródło: ransomware.live
aliorbank.pl
Financial ServicesRansomware⚠ niepotwierdzone

Szacowana data ataku: 27.04.2026 · Wykryto: 27.04.2026 16:50 UTC

Polish bank. Financial docs, internal docs. 0,06 GB of data.

Źródło: ransomware.live
Suma Sklep
Retail & E-CommerceRansomware⚠ niepotwierdzone

Szacowana data ataku: 19.04.2026 · Wykryto: 19.04.2026 17:00 UTC

Suma24.pl is a Polish B2B online store specializing in professional cleaning products, catering equipment, and hygiene systems for the HoReCa (Hotel, Restaurant, Catering) and food industry sectors. It is operated by Suma Service, a family-owned…

Źródło: ransomware.live
GL Steel
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 15.04.2026 · Wykryto: 15.04.2026 13:40 UTC

[AI generated] N/A

Źródło: ransomware.live
Uniwersytet Warszawski
EducationRansomware⚠ niepotwierdzone

Szacowana data ataku: 15.04.2026 · Wykryto: 15.04.2026 19:15 UTC

The Faculty of Management at the University of Warsaw is a leading institution in the field of business education, offering a wide range of undergraduate and graduate programs that combine theory with practical experience. However, it is not known…

Źródło: ransomware.live
M&K Foam Koło
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 05.04.2026 · Wykryto: 05.04.2026 19:16 UTC

mkfoam.pl is the official website of M&K Foam Koło, a Polish manufacturer that specializes in sleep products like mattresses and beds - corp get in touch with us, thanks.

Źródło: ransomware.live
asseco-ce.com
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 03.04.2026 · Wykryto: 03.04.2026 10:35 UTC

Country: Slovakia , Revenue: $4.4 billion Storage: 230GB Description: Asseco Central Europe (Asseco CE) is one of the strongest software houses in Central and Eastern Europe. It is active in Slovakia, the Czech Republic, Hungary, Germany, Austria…

Źródło: ransomware.live
RAKS Sp. z o.o. b Leaked
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 02.04.2026 · Wykryto: 02.04.2026 15:27 UTC

[AI generated] N/A

Źródło: ransomware.live
vegehome.pl i polskiekoldry.pl
Wyciek danych

Data wycieku: 04.2026

W kwietniu 2026 roku doszło do włamania do systemów obsługujących sklepy internetowe: vegehome.pl oraz polskiekoldry.pl, w wyniku którego osoba nieuprawniona uzyskała dostęp do bazy danych tych serwisów. Na podstawie analizy materiału potwierdzono, że wśród wykradzionych danych znajdowała się baza klientów, która została opublikowana do pobrania na jednym z forów dla cyberprzestępców. Incydent objął ponad 100 000 klientów sklepu. Dane znajdujące się w wykradzionej bazie obejmują m.in. imię i nazwisko, adres e-mail, hash hasła (bcrypt z kosztem 10), w niektórych przypadkach numer telefonu, adres zamieszkania lub adres wysyłki. Ze względu na charakter pozyskanych informacji istnieje ryzyko wykorzystania ich do ataków socjotechnicznych, takich jak spersonalizowane próby wyłudzenia danych wrażliwych.

Źródło: bezpiecznedane.gov.pl
Udemy
Wyciek danych

Data wycieku: 04.2026

W dniu 24 kwietnia 2026 roku pojawiły się informacje o nieautoryzowanym dostępie do danych użytkowników platformy Udemy. Z uzyskanych przez zespół informacji doszło do pozyskania bazy danych zawierającej około 1,4 miliona rekordów użytkowników. Zakres wykradzionych informacji dane użytkowników platformy, takie jak imię i nazwisko, adres e-mail oraz - w niektórych przypadkach - numer telefonu i inne dane kontaktowe powiązane z kontem użytkownika. Ustalono, że grupa odpowiedzialna za incydent udostępniła pozyskane dane do pobrania w Internecie, co istotnie zwiększa ryzyko ich dalszego rozpowszechniania oraz wykorzystania przez osoby trzecie. Ze względu na charakter pozyskanych danych incydent stwarza ryzyko ich wykorzystania w działaniach socjotechnicznych, w szczególności w kampaniach phishingowych oraz ukierunkowanych próbach wyłudzenia informacji.

Źródło: bezpiecznedane.gov.pl

03.2026

Paidwork
Wyciek danych

Data wycieku: 29.03.2026

In March 2026, hackers claimed they had obtained data from the gig economy platform Paidwork which they then listed for sale. Almost 11GB of data allegedly obtained from the platform was subsequently posted publicly in July and contained over 23M unique email addresses. The breach also included a broad range of other data relating to the operation of the platform including user profile data, banking information, payout history for workers and passwords stored as bcrypt hashes.

Źródło: haveibeenpwned.com
polsat.pl
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 29.03.2026 · Wykryto: 29.03.2026 01:40 UTC

Country: Poland Revenue: $148.5 Million Storage: 75.71 GB Description: Polsat is t he first independent TV station in Poland. The main objective of Polsat is to meet the varied tastes of the general public. The program offer is built primarily on…

Źródło: ransomware.live
SYSTHERM INFO
TechnologyRansomware⚠ niepotwierdzone

Szacowana data ataku: 26.03.2026 · Wykryto: 19.04.2026 17:09 UTC

systherm-info.pl Systherm Info Sp. z o.o. is a Polish IT company headquartered in Poznan, founded in 1996. It specializes in GIS (Geographic Information Systems), IT solutions, and software security — most notably developing GEO-INFO, a leading land…

Źródło: ransomware.live
Salag
Not FoundRansomware⚠ niepotwierdzone

Szacowana data ataku: 15.03.2026 · Wykryto: 15.03.2026 19:43 UTC

Źródło: ransomware.live
Estra Automotive
ManufacturingRansomware⚠ niepotwierdzone

Szacowana data ataku: 10.03.2026 · Wykryto: 10.03.2026 01:23 UTC

Estra Automotive is an international automotive supplier that develops and manufactures thermal management components and systems for vehicles. The company focuses on products such as HVAC systems, heat exchangers, and engine cooling solutions used…

Źródło: ransomware.live
Towarzystwo Opieki nad Ociemniałymi
Wyciek danych

Data wycieku: 03.2026

W marcu 2026 roku doszło do nieuprawnionego dostępu do zasobów baz danych powiązanych z infrastrukturą sieciową Towarzystwa Opieki nad Ociemniałymi. W wyniku incydentu osoba nieuprawniona mogła uzyskać dostęp do baz zawierających dane osobowe, w tym dane kontaktowe oraz imię i nazwisko. Na podstawie dostępnych informacji ustalono, że wykradziona baza danych nie została na ten moment nigdzie opublikowana. Ze względu na zakres pozyskanych danych istnieje ryzyko ich wykorzystania w przyszłych próbach wyłudzeń oraz atakach socjotechnicznych. Ze względu na charakter pozyskanych informacji istnieje ryzyko wykorzystania ich do ataków socjotechnicznych, takich jak spersonalizowane próby wyłudzenia danych wrażliwych.

Źródło: bezpiecznedane.gov.pl