A cyberattack on Poland’s Witold Pilecki Institute of Solidarity and Valor gave attackers access to the institution’s online resources, which were then used to publish Russian propaganda, including anti-Ukrainian material.
The incident, reported on 17 August 2026 by CyberDefence24, went beyond disrupting the work of a Polish public institution. The attackers used its information channels to present Kremlin-aligned narratives as if they formed part of Poland’s own official information space.
An attack aimed at credibility as well as access
The Pilecki Institute is a Polish institution whose public standing gave the compromised channels particular value to those behind the intrusion. By publishing material through a recognised organisation, the attackers sought to exploit the authority associated with an established state institution rather than distribute the same messages through an obviously hostile or anonymous platform.
The operation therefore had two connected purposes: gaining access to the institute’s digital resources and using that access to influence public perceptions. The disruption of the institution’s normal communications was important, but the publication of propaganda was the more significant element. It turned the institution’s own platforms into tools for spreading messages designed to shape political attitudes in Poland.
The material included anti-Ukrainian narratives. Their appearance on a hacked Polish resource risked making them look like an expression of domestic Polish opinion, rather than part of a Russian information operation. That distinction matters in a country where public institutions are expected to provide authoritative information and where the credibility of official channels is central to public trust.
A wider hybrid threat to Poland
The attack illustrates the growing hybrid threat facing Poland from Russia. Digital systems are not being treated only as targets whose operation can be interrupted. They can also be used as channels for political influence, allowing hostile actors to borrow the identity and legitimacy of the institution they have compromised.
Such activity can deepen suspicion towards government bodies and make it harder for people to distinguish between a genuine institutional statement and content inserted by an attacker. The damage is consequently not limited to the period during which a website or other resource is under the attackers’ control. It can also weaken confidence in official communications after the intrusion has ended.
The choice of anti-Ukrainian themes gave the attack a further strategic purpose. Those messages can intensify existing historical and political disputes between Poland and Ukraine, while presenting hostility towards Ukraine as part of the Polish information debate. In that form, the cyberattack becomes an attempt to influence relations between societies, not simply a technical assault on one organisation.
Pressure on Polish-Ukrainian cooperation
Russia’s use of anti-Ukrainian narratives in compromised Polish institutional resources follows a broader information strategy aimed at weakening cooperation between Poland and Ukraine. By aggravating disagreements and amplifying messages that divide the two countries, the campaign seeks to undermine support for Ukraine in Poland.
The risk is especially serious because the messages are delivered through a channel that appears Polish and institutional. A reader encountering the material on the institute’s resources could interpret it as evidence of an official or mainstream position, even though the content was placed there by attackers. This gives the operation an advantage over conventional propaganda, which is more easily identified by its source.
The incident shows why cyber security and information security cannot be separated. Protecting a public institution’s systems is also a way of protecting the reliability of its public voice. When attackers can seize both, they can disrupt operations, impersonate the institution and exploit sensitive political divisions at the same time.
For Poland, the immediate challenge is to prevent trusted public channels from becoming instruments of foreign influence. The broader question is whether the country’s institutions and public can maintain confidence in official information when Russia is able to use a cyber intrusion to place divisive narratives inside it.
How should Poland respond when a cyberattack targets not only an institution’s systems but also the credibility of its public voice?