Poland’s Minister of Digital Affairs, Krzysztof Gawkowski, announced on Thursday (12 March 2026) that a cyberattack had targeted the servers of the National Centre for Nuclear Research (NCBJ).
“Malicious software was identified on one of the institution’s workstations,” the minister wrote on his profile on the X platform. In an interview with TVN24, he added that “the first identified entry vectors — meaning the locations from which the attack originated — appear to be linked to Iran,” although he stressed that such traces could also be part of deliberate camouflage.
Expert Commentary
Kamil Sadkowski, cybersecurity expert at ESET:
“In 2026, distance in cyberspace has effectively ceased to exist. Highly professional and well-organized groups linked to governments — so-called APT (Advanced Persistent Threat) groups — are operating intensively. ESET data are alarming: pro-Iranian groups already account for nearly 8% of documented APT attacks worldwide (source: APT Activity Report, April 2025 – September 2025), and their activity is increasing in light of the current geopolitical situation.
Although their traditional target remains Israel, we are observing a rapid expansion of operations toward Europe, including countries such as Greece and Cyprus, among others.
Iranian APT groups frequently use well-known but still unfortunately effective techniques, including phishing and ransomware. Campaigns we analysed, for example those conducted in June 2025 targeting engineering and energy sectors, demonstrate the precision of these operations.
For APT groups, critical infrastructure and research centres are priority targets not only because of their potential to disrupt state operations, but above all because of their intelligence value. We must understand that cyber conflicts inevitably follow kinetic conflicts, and Poland — due to its geographical location and geopolitical engagement — is today on the front line of this invisible war.
In this context it is worth recalling, for example, the December 2025 attack on a Polish combined heat and power plant, which became a target of a Russia-linked APT group, as well as the recent ransomware attack on a hospital in Szczecin.”
Source: Manager Plus





