Expert advice
Hacking Charges in Poland: Unauthorized System Access
04.09.2026
Unauthorized system access is the act of entering all or part of an IT system without permission. In Poland, this conduct is commonly described as hacking, although “hacking” is not a separate statutory offence. Depending on the facts, computer intrusion may be prosecuted primarily under Article 267 of the Polish Penal Code.[1]
For companies, hacking charges Poland cases can involve much more than an external cyber attack. Criminal exposure may arise from employee activity, former contractors retaining credentials, unauthorised use of administrator accounts, access to customer databases, or penetration testing conducted outside the agreed scope. The key issue is usually whether access was authorised at the relevant time and for the specific system, account, data or purpose.
Unauthorized access under Article 267 of the Polish Penal Code
Article 267 § 2 of the Penal Code criminalises gaining access, without authorisation, to all or part of an information system. The offence may be committed even where the person does not copy, delete, alter or publish data. Access itself can be sufficient if it was obtained without permission.
Article 267 § 1 addresses obtaining information not intended for the perpetrator by, among other methods, bypassing electronic, magnetic or other special security measures. This may include breaking a password, using stolen login data, exploiting a vulnerability, bypassing multi-factor authentication, or accessing protected correspondence.
The statutory penalty for conduct under Article 267 § 1 or § 2 is a fine, restriction of liberty, or imprisonment for up to two years. The offence is prosecuted upon the motion of the injured party under Article 267 § 5.[1] In practice, this means that the affected individual or organisation must usually submit a formal request for prosecution.
What prosecutors examine in computer intrusion cases
In an unauthorised access investigation, prosecutors generally assess the technical evidence together with the business and contractual context. The fact that a person previously had access to a system does not automatically mean that access remained lawful.
Relevant evidence may include:
- system, server, VPN and application logs;
- authentication records and IP address data;
- employment contracts, IT policies and access-management procedures;
- authorisations granted to employees, suppliers or external consultants;
- messages concerning the scope of work or the purpose of access;
- forensic copies of devices, accounts and cloud environments;
- evidence of copied, modified, encrypted or exfiltrated data.
A cyber attack may therefore create both criminal and operational consequences. A company may need to secure evidence, maintain business continuity, assess data-protection implications, notify insurers, and decide whether to make a criminal complaint. Delayed action can result in loss of log data and weaken the ability to identify the person responsible.
Three situations that may exclude unauthorised access
Polish law does not provide a universal list of “hacking exceptions.” Whether access was authorised depends on the facts. However, three situations are particularly important when assessing whether Article 267 may apply.
1. Clear consent from the authorised system owner or administrator
Access is not unauthorised where valid permission was granted by a person entitled to manage the system or the relevant data. Consent should define who may access the system, which accounts or environments are covered, and for what purpose. General permission to use company IT resources does not necessarily authorise access to HR records, financial systems or confidential customer databases.
2. Access based on statutory powers and procedural rules
Public authorities may access data or systems only where a specific legal basis and applicable procedural requirements exist. The assessment depends on the authority involved, the type of data, and the measures used. Lawful investigative activity should not be confused with private monitoring, unauthorised surveillance or informal access to another person’s account.
3. Access to information made genuinely public
Viewing information intentionally published without access restrictions is different from entering a protected system. However, publicly available content does not permit access to hidden panels, databases, source environments, administrative functions or technical resources that are not intended for public use. The boundary may be fact-sensitive, particularly where a website contains misconfigured but non-public resources.
Related cybercrime offences in Poland
Unauthorised access may be accompanied by other offences. Article 268a concerns destroying, damaging, deleting, altering or obstructing access to computer data. Article 269a addresses serious interference with an information system or network, including conduct that significantly disrupts operations. Article 269b criminalises the production, acquisition, sale or provision of devices or software adapted to commit certain computer offences.[1]
If access is used to obtain a financial benefit or cause financial loss through interference with data processing, Article 287 on computer fraud may also be relevant. Where personal data are involved, the company must separately assess obligations under the General Data Protection Regulation, including whether a personal data breach requires notification to the supervisory authority or affected individuals.[2]
Business response to suspected hacking or unauthorised access
An organisation should avoid immediately deleting accounts, devices or logs without preserving evidence. Containment is necessary, but evidence preservation is equally important for internal proceedings, insurance claims and possible criminal action.
- Secure logs, devices, access records and relevant communications.
- Limit access and reset credentials where continued intrusion is possible.
- Establish the scope of accessed systems, data and business impact.
- Review contracts, permissions and internal IT policies.
- Assess whether notification duties arise under data-protection or sectoral rules.
- Consider filing a motion for prosecution and supporting it with preserved evidence.
In complex cases, legal analysis should be coordinated with digital forensics. Kopeć & Zaborowski (KKZ) supports businesses in criminal-law assessments, crisis response, internal investigations and matters involving cybercrime. This is informational material, not legal advice.
For criminal cases concerning hacking or other cybercrime, it may be useful to consult the matter with a lawyer, obtain an assessment of the situation and discuss possible steps. Early analysis may be important where evidence is digital, volatile or subject to confidentiality obligations.
FAQ – Hacking Charges in Poland
Is hacking a separate criminal offence in Poland?
No. “Hacking” is a common term. Unauthorised system access is usually assessed under Article 267 of the Polish Penal Code, although other provisions may apply depending on the conduct and consequences.
Can an employee face hacking charges for accessing company systems?
Yes. An employee may face criminal risk if access exceeds granted permissions, concerns systems outside the employee’s role, or continues after employment or authorisation ends.
Is using another person’s password a criminal offence?
It may be. Using another person’s credentials without authorisation can constitute unauthorised access, particularly if it enables entry into a protected system or access to information not intended for that person.
Does copying data have to occur for Article 267 to apply?
No. Under Article 267 § 2, gaining unauthorised access to all or part of an information system may itself be sufficient. Copying, deleting or publishing data can lead to additional liability.
Can a company report a former employee for unauthorised access?
Yes, if evidence indicates that the former employee accessed company systems after permissions were withdrawn or used retained credentials without authority. Logs, offboarding records and access-control documentation are particularly relevant.
Is penetration testing legal in Poland?
It can be legal if carried out under clear authorisation. A written agreement should define the systems, dates, methods, permitted testing activities, reporting process and emergency contacts. Testing outside the agreed scope may create criminal risk.
Bibliography
- [1] Act of 6 June 1997 – Penal Code (Poland), in particular Articles 267, 268a, 269a, 269b and 287, consolidated text available through the Internet System of Legal Acts (ISAP).
- [2] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – General Data Protection Regulation, in particular Articles 33 and 34.
- [3] Convention on Cybercrime, Budapest, 23 November 2001, Council of Europe Treaty Series No. 185.
Need help?
Expert advice
Surveillance and Wiretapping in Poland: Defense Strategies
Surveillance and Wiretapping in Poland: Defense StrategiesSIM Swapping and Phone Fraud in Poland: Criminal Threat
SIM Swapping and Phone Fraud in Poland: Criminal ThreatDigital Evidence in Polish Criminal Cases: Admissibility
Digital Evidence in Polish Criminal Cases: AdmissibilityHow can
we help you?
the experts