Wednesday, September 02, 2026

Kremlin-linked cyber campaign targets Polish state services

September 1, 2026
2 mins read
Kremlin-linked cyber campaign targets Polish state services
Kremlin-linked cyber campaign targets Polish state services

Pro-Russian hackers have launched a series of DDoS attacks against Polish government institutions, targeting services used by citizens and public authorities.

The attacks, reported on 31 August 2026, were carried out by the pro-Russian group Server Killers against Poland’s Ministry of Justice, public electronic services, European Social Fund systems, the EU Emissions Trading System and other administrative resources. The campaign shows how the Kremlin’s hybrid pressure on European countries supporting Ukraine is extending through cyberspace. ITwiz reported the incidents, citing research by Check Point.

According to Check Point, the purpose of the attacks was to overwhelm servers and temporarily block access to public services. The operation was not primarily aimed at stealing information. Instead, it sought to disrupt the normal functioning of state systems, expose their vulnerability and create pressure on the public and the institutions responsible for keeping essential digital services available.

A campaign built around disruption

Distributed denial-of-service, or DDoS, attacks work by sending large volumes of traffic towards a targeted website or network. The resulting overload can make a service slow, unstable or unavailable to legitimate users. In this case, the choice of targets gave the campaign a wider political significance than an attack on a single commercial website.

The Ministry of Justice represents a central state institution, while public electronic services provide an important point of contact between citizens and government. The targeting of European Social Fund systems and the emissions-quota trading system also reached into administrative mechanisms connected with wider European activity. Together, the targets suggested an attempt to demonstrate that digital infrastructure supporting both national administration and European programmes could be placed under strain.

Server Killers’ actions fit a model in which pro-Russian hacker groups use cyber operations as an instrument of political pressure against countries that support Ukraine. The immediate effect of a DDoS attack may be temporary, but repeated disruption can force public bodies to devote substantial time and resources to defence, while raising public concern about the reliability of state services.

Pressure on Poland’s defensive capacity

For Poland, the intensity of the threat creates a continuing burden for the systems responsible for cyber protection. Each new attack requires monitoring, mitigation and the strengthening of vulnerable services. Even where disruption is temporary, the need to maintain defensive capacity across a large number of government platforms places sustained demands on the state.

That pressure matters because digital security can no longer be treated as a separate technical issue. The attacks demonstrate that the resilience of online public services is part of national security and, increasingly, part of European defence. A government’s ability to provide access to justice, administrative systems and public information depends not only on physical institutions but also on the networks through which those services are delivered.

The campaign also illustrates the strategic value of disruption for an adversary seeking to impose costs without carrying out a conventional attack. Blocking access, even temporarily, can create uncertainty while allowing the perpetrators to claim that state institutions are exposed. The broader objective is therefore not limited to the servers directly targeted: it is to test confidence in the authorities’ ability to protect essential infrastructure.

A wider European challenge

The consequences extend beyond Poland’s borders. European governments share digital systems, standards and security concerns, and a sustained campaign against one member state can provide information about weaknesses that may be relevant elsewhere. The attacks therefore strengthen the case for deeper information-sharing on cyber threats, coordinated responses and stronger resilience across government infrastructure throughout the EU.

For European countries supporting Ukraine, the incident is a reminder that pressure can be applied below the threshold of a conventional conflict. Cyber operations can be repeated, adjusted and directed at public-facing services, creating a persistent test of institutional readiness. The unresolved question is whether European states can coordinate their defences quickly enough to prevent isolated attacks from becoming a sustained weakness in the continent’s public infrastructure.

Should the EU prioritise a shared system for responding to attacks on public services, or should responsibility remain primarily with individual member states?

Leave a Reply

Your email address will not be published.

Don't Miss

Burnham warns reversing water privatisation will be challenging for his administration

Burnham warns reversing water privatisation will be challenging for his administration

Prime Minister warns of challenges in reversing water industry privatisation Prime Minister
Richard Engel returns to Ukraine amid intensified conflict following deadly strike near Kyiv

Richard Engel returns to Ukraine amid intensified conflict following deadly strike near Kyiv

Richard Engel is back in Ukraine to report on its intensifying war