Poland is among the countries that, according to the European Union and NATO, have been targeted by Russian cyberattacks and hybrid operations against critical infrastructure. Brussels has explicitly stated that Russia’s 16th FSB Centre allegedly conducted sabotage operations against Polish combined heat and power plants and other elements of the country’s infrastructure. Check Point Research also confirms that the number of cyberattacks targeting Poland’s public sector has risen sharply in recent months.
The European Union has announced another round of sanctions against nine individuals and four organisations linked to Russian cyber operations. The measures target people and entities cooperating with Russia’s GRU military intelligence service.
Those added to the sanctions list include hackers, cybercriminals, Russian companies and organisations associated with the GRU. Among them are Media Land, its sister company and Impuls, a company linked to Russian military intelligence.
According to the EU statement, Russia has been responsible for years of cyberattacks against public administration, the energy and defence sectors, and scientific and research institutions across EU member states.
EU High Representative for Foreign Affairs and Security Policy Kaja Kallas said on behalf of the member states that Russia was responsible for cyberattacks targeting public authorities, diplomatic missions, critical infrastructure in the defence and energy sectors, and scientific, research and educational institutions.
Russian FSB unit linked to operations against Poland
The part of the statement concerning Poland is particularly alarming. Brussels said that the FSB’s 16th Centre had allegedly carried out destructive activities against Polish critical infrastructure, including combined heat and power plants.
This is the first such explicit statement from EU institutions identifying a specific Russian structure as being responsible for cyber operations directed against Poland.
Technological data also points to a growing threat. According to the latest monitoring by Check Point Research, Poland’s public administration sector has, for the second time this year, been targeted by more than 3,100 cyberattacks per week.
This was the highest level among all industries analysed and significantly exceeded the national average of 1,775 attacks per organisation per week. The national figure represents a 3% increase compared with the previous year.
Check Point analysts emphasise that energy companies and the business services sector are also under particularly intense pressure. These areas are considered crucial to the functioning of the state and to national economic security.
“All such operations have one common objective: to cause a greater or lesser degree of paralysis in the functioning of the state,” said Wojciech Głażewski, Country Manager of Check Point Software in Poland.
“In the current geopolitical environment, cyberattacks have become an element of strategic security. Russian groups seek to disrupt the work of public institutions, increase the sense of uncertainty and destabilise a country that actively supports Ukraine.”
State-sponsored attacks go beyond ordinary cybercrime
Experts note that modern state-sponsored operations differ from conventional cybercrime. Their objective is not merely to steal data or money, but to infiltrate public administration and critical infrastructure systems over long periods, identify vulnerabilities and prepare possible acts of sabotage.
For this reason, continuous threat monitoring by specialist analytical centres is particularly important.
Poland’s Ministry of Foreign Affairs supported the joint position of the EU and NATO, stressing that Russia uses a network of intelligence services, hacking groups and private companies to conduct destabilisation operations against European Union and NATO countries.
“Poland welcomes the statements issued by the European Union and NATO, through which, together with our allies, we expose and condemn Russia’s hostile activities in cyberspace,” the Foreign Ministry said.
“The system described is used to conduct destructive activities and influence operations aimed at destabilising the structures and decision-making processes of European Union and NATO countries,” the ministry added.
At the same time, France and Germany summoned the Russian ambassadors, while the United Kingdom announced further sanctions against individuals and entities responsible for Russian cyberattacks.





