/
    Zpět na blog
    Security Sunday

    Poland Under Fire from Hackers: Cyberattack on a Nuclear Research Center


    Poland Under Fire from Hackers: Cyberattack on a Nuclear Research Center

    The Polish National Centre for Nuclear Research (NCBJ) has become the target of a cyberattack aimed at its IT infrastructure. In Security Sunday, we also cover Operation Synergia III taking down 45,000 malicious IP addresses, Operation Lightning dismantling the SocksEscort botnet, and hacker group ShinyHunters stealing nearly a petabyte of data from Telus Digital.

    image

    The Polish National Centre for Nuclear Research (NCBJ) has become the target of a cyberattack aimed at its IT infrastructure.

    "Security systems and internal procedures, designed specifically for early threat detection, enabled IT teams to quickly secure the compromised systems and maintain the full integrity of the entire infrastructure. The MARIA research reactor, Poland's only nuclear reactor used for scientific experiments, was not affected by the attack in any way and continues to operate safely at full capacity," stated the Center's Director, Professor Jakub Kupecki.

    Polish Deputy Prime Minister and Minister of Digitalization Krzysztof Gawkowski confirmed that initial analyses of the attack's entry vectors point to a possible connection to Iran. However, he strongly cautioned that these indicators could be a deliberate diversionary tactic — a so-called false flag — aimed at diverting attention from the real perpetrators. This caution is well-founded, especially since Poland has no direct conflict with Iran. Polish Minister of Defense Władysław Kosiniak-Kamysz explicitly emphasized that his country does not participate in military operations in the Middle East.

    The attack on the nuclear research center is not an isolated incident, however. In recent months, Poland has become one of the most frequently targeted European countries in cyberspace. A report by the International Centre for Counter-Terrorism (ICCT) from late February 2026 ranked Poland high on the list of targets of Russian cyber actors, attributing 31 confirmed incidents to them in the period from mid-2025 to early 2026.

    The most serious cyber incident in Poland's recent history was the coordinated attack on energy infrastructure on December 29, 2025, which was covered in a previous issue of Security Sunday.

    Operation Synergia III: 45,000 Malicious IP Addresses Taken Down and 94 Suspects Arrested

    INTERPOL, in cooperation with security forces from 72 countries worldwide, launched the most extensive coordinated operation to date aimed at dismantling infrastructure used by cybercriminals. The operation, codenamed Synergia III, ran from July 18, 2025, to January 31, 2026, and its results are truly impressive: law enforcement agencies neutralized more than 45,000 malicious IP addresses and servers that were being used to spread phishing, malware, and ransomware around the world.

    During the operation, a total of 94 suspects were arrested, and another 110 remain on investigators' radar. A total of 212 electronic devices and servers used by criminals to operate fraudulent websites and malware command-and-control servers were seized.

    Particularly notable results came from Bangladesh, where police detained 40 suspects and seized 134 electronic devices linked to loan scams, fake job offers, identity theft, and credit card fraud. In Togo, security forces dismantled a ten-member fraud gang operating from a residential neighborhood, specializing in hacking social media accounts and romance scams.

    One of the most interesting findings of the operation was the discovery of more than 33,000 phishing and fraudulent websites in Macau. These sites impersonated legitimate casinos, banks, government portals, and payment services.

    The cooperation between INTERPOL and leading cybersecurity companies — specifically Group-IB, Trend Micro, and S2W — played a crucial role in the operation's success. These firms helped track illegal cyber activities, identify malicious servers, and map entire criminal ecosystems. As Robert McArdle from Trend Micro emphasized, "behind every malicious server or phishing tool lies a larger criminal network that must first be understood and mapped."

    Operation Synergia III is already the third phase of this global campaign against cybercrime. The first wave took place in the fall of 2023 and led to the removal of approximately 1,300 command-and-control servers and the identification of 70 suspects across 52 participating countries. The second phase in 2024 resulted in 41 arrests and impacted infrastructure linked to 22,000 IP addresses. The third phase surpassed these results many times over. The number of participating countries grew to 72, and the number of neutralized IP addresses climbed above 45,000.

    Operation Lightning: International Crackdown on the SocksEscort Botnet

    Staying with law enforcement successes — agencies from eight countries joined forces under the codename Operation Lightning to dismantle the SocksEscort service.

    SocksEscort operated as a residential proxy. Its operators infected routers and IoT devices with malware called AVrecon, turning them — without their owners' knowledge — into anonymous exit nodes for criminal traffic. Customers could purchase access to these infected devices using cryptocurrency and route their internet traffic through them. This allowed their real IP addresses and locations to be hidden behind legitimate home connections. The service reportedly offered access to approximately 369,000 different IP addresses in 163 countries.

    The attackers targeted 1,200 device models from manufacturers such as Cisco, D-Link, Hikvision, MikroTik, Netgear, TP-Link, and Zyxel. The malware exploited known vulnerabilities to penetrate unprotected routers. After a successful infection, AVrecon was able to permanently embed itself in the device by overwriting the router's firmware with a custom version containing a copy of the malware. This modified firmware also blocked the ability to update, leaving the device permanently infected.

    Hacker Group ShinyHunters Stole Nearly a Petabyte of Data from Telus Digital

    Canadian telecommunications giant Telus confirmed on March 12, 2026, a serious cyber incident affecting its subsidiary Telus Digital. According to the hacker group ShinyHunters, which claimed responsibility for the attack, nearly one petabyte of data was stolen. If confirmed, this would be one of the largest data breaches in history.

    According to available information, ShinyHunters obtained login credentials for the Google Cloud platform from data stolen during an earlier breach of the Salesloft Drift service.

    Using these credentials, the attackers gained access to a large BigQuery database and then used the open-source tool TruffleHog, which is designed to find forgotten access tokens and passwords in datasets. The discovered credentials then allowed them to penetrate additional internal systems and download massive volumes of data over several months without being detected.

    According to ShinyHunters, the stolen material includes customer support records, phone call recordings, proprietary software source code, call center agent performance data, financial documents, Salesforce data, and even FBI security clearance results for employees. Because Telus Digital operates as an outsourcing service provider for dozens of large companies, the breach also impacts their clients.

    © 2026 Patrik Žák. Všechna práva vyhrazena.