Local government units in Poland have become the target of a coordinated phishing campaign, in which cybercriminals are impersonating the Ministry of Digital Affairs and Deputy Minister Paweł Olszewski. The goal of the attacks is to steal contact data of municipal employees or infect their devices with malicious software. The warning was issued by Krzysztof Gawkowski, the Government Plenipotentiary for Cybersecurity.
Government Warning: Beware of Fake Emails
In an official statement, the Government Plenipotentiary for Cybersecurity announced the discovery of a new phishing campaign directed against local government institutions.
The fraudulent emails are being sent from the domain govministry[.]pl, which closely resembles legitimate government addresses but is not associated with any public authority.
The messages pretend to come from the Ministry of Digital Affairs or directly from Deputy Minister Paweł Olszewski. Their content typically urges recipients to take immediate action — for example, to confirm contact information for individuals responsible for cybersecurity within their office, or to open an attached file allegedly containing official documents.
Two Variants of the Attack
Experts have identified two main variants of the ongoing campaign:
- Malware Distribution
The email contains an attachment (e.g., a PDF, DOCX, or ZIP file) which, when opened, installs malicious software.
The malware can allow criminals to gain remote access to the office’s IT systems, steal sensitive data, or take control of user accounts. - Data Harvesting
In this version, the email asks recipients to provide information about cybersecurity officers — including their names, phone numbers, and email addresses.
These details may then be used to conduct more sophisticated social engineering attacks or targeted spear-phishing campaigns in the future.
“Such attacks are particularly dangerous because they exploit the public’s trust in official institutions and government officials,” said Krzysztof Gawkowski in the statement.
“I urge all local government units to exercise extreme caution — always verify the source of incoming messages and report any suspicious activity to your security teams.”





