• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

Cross-Border Cybercrime: Poland’s International Cooperation

24.09.2026

Cross-border cybercrime is criminal activity committed through information systems where the offender, victim, digital infrastructure, evidence or financial proceeds are located in more than one country. It may involve unauthorised access to systems, ransomware, phishing, business email compromise, data theft, online fraud or attacks on critical infrastructure.

For businesses, the international dimension is often the main obstacle to an effective response. A company may discover an intrusion in Poland, while the attacker uses servers in another jurisdiction, cryptocurrency exchanges outside the European Union and accounts opened under false identities in several countries. Securing evidence quickly and choosing the correct cooperation mechanism can determine whether the incident leads to identification of the perpetrators, recovery of assets or only internal loss mitigation.


Cross border cybercrime Poland – why jurisdiction matters

Polish criminal law may apply even where part of the conduct occurred abroad. The assessment depends on the place of the act, the effects of the conduct, the nationality of the suspect, the nationality of the victim and applicable international agreements. Under Article 6 of the Polish Criminal Code, an offence is considered committed in Poland where the perpetrator acted or omitted to act, or where the criminal result occurred or was intended to occur.[1]

Cybercrime can therefore fall within Polish jurisdiction when, for example, a Polish company’s network is attacked, fraudulent payment instructions cause a loss in Poland, or malware is deployed from Poland against foreign systems. Further jurisdictional rules are set out in Articles 109-113 of the Criminal Code. In some situations, prosecution of conduct committed abroad requires dual criminality, meaning that the conduct must also be an offence in the country where it was committed.[1]

Common provisions used in cybercrime cases include Article 267 of the Criminal Code, concerning unlawful access to information, Articles 268 and 268a, concerning interference with data, and Article 269a, concerning disruption of an IT system, data communication system or network.[1] Fraud schemes may also be assessed under Article 286, while document, money laundering and organised crime provisions can apply depending on the facts.


International cooperation mechanisms used by Poland

Polish prosecutors, police and courts do not conduct investigative measures abroad independently. They request assistance through European Union mechanisms, international conventions, bilateral treaties or diplomatic channels. The appropriate route depends on the requested measure, the state involved, urgency and the location of the evidence.

European Investigation Order within the European Union

Within the EU, an important instrument is the European Investigation Order (EIO). It allows judicial authorities in one Member State to request another Member State to carry out specified investigative measures, such as obtaining subscriber data, hearing a witness, securing records, searching premises or collecting digital evidence. The EIO is based on Directive 2014/41/EU and was implemented into Polish criminal procedure.[2]

For corporate victims, an EIO may be relevant where payment records are held by a foreign bank, a cloud service provider is established in another Member State or an employee who received fraudulent communications is located abroad. The request must be specific, proportionate and legally justified. Broad or poorly defined requests can delay proceedings or be refused.

Mutual legal assistance outside the EU

Where evidence is located outside the EU, Poland may use mutual legal assistance. Article 589a of the Polish Code of Criminal Procedure provides a general basis for requests for legal assistance in criminal matters, subject to applicable international agreements and reciprocity.[3]

The 2001 Budapest Convention on Cybercrime is particularly important. It provides a framework for cooperation in cases involving computer systems and electronic evidence. The Convention requires parties to maintain a 24/7 network for urgent assistance and addresses expedited preservation of stored computer data, production orders, search and seizure of stored data, and transborder access in limited circumstances.[4]

Preservation is often the decisive step. Log files, IP address allocation records, account data and cloud-hosted materials may be deleted under standard retention policies before a formal request is completed. An incident response plan should therefore distinguish between immediate evidence-preservation actions and later disclosure requests.


Europol cyber support and Eurojust coordination

Europol cyber cooperation supports national law enforcement authorities rather than replacing them. Europol’s European Cybercrime Centre, known as EC3, assists Member States through intelligence analysis, operational coordination, information exchange and support for joint action against cyber-enabled crime.[5] Europol does not itself prosecute suspects or issue binding investigative orders.

Eurojust has a different role. It supports judicial cooperation between prosecutors and courts, particularly in complex cases involving multiple jurisdictions. Eurojust can help resolve conflicts of jurisdiction, organise coordination meetings and assist in establishing joint investigation teams (JITs).[6]

A JIT can be effective in ransomware, large-scale phishing and investment fraud cases where authorities in several states investigate the same network. It enables participating authorities to share information and evidence more directly within the agreed framework. It does not remove the need to comply with procedural safeguards, data-protection rules and the terms of the JIT agreement.


International prosecution and the limits of cooperation

International prosecution is not automatic merely because an incident is global. Authorities must establish jurisdiction, identify an offence under applicable law and meet the evidential threshold for particular measures. The requested state may refuse or limit assistance on grounds provided by its law or by the relevant treaty, including sovereignty, public policy, proportionality, fundamental rights or insufficient specificity of the request.

Three practical limitations should be considered from the outset:

  • Data location is not always clear. Cloud services may distribute data across several states, and a provider’s registered office may differ from the location of relevant servers.
  • Evidence is volatile. IP logs, session data and cryptocurrency records can become unavailable quickly, while formal international requests may take time.
  • Procedural standards differ. Evidence lawfully collected abroad may still require careful assessment before it can be used effectively in Polish proceedings.

Businesses should avoid conducting their own intrusive investigation. Accessing an employee’s private account, tracing an attacker through unauthorised tools or publicising unverified allegations can create separate legal exposure. A controlled forensic process, preservation of original records and a clear chain of custody are usually more valuable than immediate but unreliable attribution.

KKZ lawyers support companies and individuals in cybercrime matters involving criminal notifications, protection of evidence, communication with authorities and assessment of cross-border procedural options. More information on the scope of support is available at cybercrime legal services.

This is informational material, not legal advice. The appropriate course of action depends on the facts, the jurisdictions involved and the available evidence.


For criminal matters concerning cybercrime, it may be useful to consult the matter with a lawyer and obtain an assessment of the situation. Early discussion can help identify possible procedural steps and evidence-related issues.


FAQ – Cross-Border Cybercrime

Can Poland prosecute a cyberattack carried out from another country?

Potentially, yes. Polish jurisdiction may arise where the criminal result occurred or was intended to occur in Poland, for example where a Polish company suffered a loss or its IT systems were targeted. The final assessment depends on the facts and the applicable jurisdictional rules.

What is the fastest way to secure foreign electronic evidence?

Urgent preservation of data is usually the first priority. Under the Budapest Convention framework, authorities may use 24/7 contact points and preservation procedures. A formal disclosure request may follow after the relevant data has been preserved.

What is the role of Europol in cybercrime cases?

Europol supports national authorities with intelligence, analysis and operational coordination. It does not replace Polish prosecutors or courts and does not independently prosecute offenders.

Can a Polish prosecutor obtain evidence from another EU Member State?

Yes. The European Investigation Order may be used to request defined investigative measures in another participating EU Member State, subject to legal conditions and possible grounds for refusal.

Does a company need to wait for the police before preserving evidence?

No. A company should preserve relevant logs, emails, devices, payment records and system images promptly, while avoiding any action that alters original data. Forensic collection should be documented carefully.

Can cryptocurrency assets connected with cybercrime be recovered internationally?

Recovery may be possible, but it depends on tracing the assets, identifying the relevant exchange or custodian, securing evidence and obtaining appropriate freezing or confiscation measures in the relevant jurisdictions.


Bibliography

  • [1] Act of 6 June 1997 – Polish Criminal Code, consolidated text: Journal of Laws 2024, item 17, as amended, in particular Articles 6, 109-113, 267, 268, 268a, 269a and 286.
  • [2] Directive 2014/41/EU of the European Parliament and of the Council of 3 April 2014 regarding the European Investigation Order in criminal matters.
  • [3] Act of 6 June 1997 – Polish Code of Criminal Procedure, consolidated text: Journal of Laws 2024, item 37, as amended, in particular Article 589a.
  • [4] Convention on Cybercrime, Budapest, 23 November 2001, Council of Europe Treaty Series No. 185.
  • [5] Regulation (EU) 2016/794 of the European Parliament and of the Council of 11 May 2016 on the European Union Agency for Law Enforcement Cooperation (Europol).
  • [6] Regulation (EU) 2018/1727 of the European Parliament and of the Council of 14 November 2018 on the European Union Agency for Criminal Justice Cooperation (Eurojust).

Need help?

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

contact@kkz.com.pl

+48 509 211 000

Expert advice

Surveillance and Wiretapping in Poland: Defense Strategies

Read more
Surveillance and Wiretapping in Poland: Defense Strategies

SIM Swapping and Phone Fraud in Poland: Criminal Threat

Read more
SIM Swapping and Phone Fraud in Poland: Criminal Threat

Digital Evidence in Polish Criminal Cases: Admissibility

Read more
Digital Evidence in Polish Criminal Cases: Admissibility
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm