• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

Hacking Charges in Poland: Unauthorized System Access

04.09.2026

Unauthorized system access is the act of entering all or part of an IT system without permission. In Poland, this conduct is commonly described as hacking, although “hacking” is not a separate statutory offence. Depending on the facts, computer intrusion may be prosecuted primarily under Article 267 of the Polish Penal Code.[1]

For companies, hacking charges Poland cases can involve much more than an external cyber attack. Criminal exposure may arise from employee activity, former contractors retaining credentials, unauthorised use of administrator accounts, access to customer databases, or penetration testing conducted outside the agreed scope. The key issue is usually whether access was authorised at the relevant time and for the specific system, account, data or purpose.


Unauthorized access under Article 267 of the Polish Penal Code

Article 267 § 2 of the Penal Code criminalises gaining access, without authorisation, to all or part of an information system. The offence may be committed even where the person does not copy, delete, alter or publish data. Access itself can be sufficient if it was obtained without permission.

Article 267 § 1 addresses obtaining information not intended for the perpetrator by, among other methods, bypassing electronic, magnetic or other special security measures. This may include breaking a password, using stolen login data, exploiting a vulnerability, bypassing multi-factor authentication, or accessing protected correspondence.

The statutory penalty for conduct under Article 267 § 1 or § 2 is a fine, restriction of liberty, or imprisonment for up to two years. The offence is prosecuted upon the motion of the injured party under Article 267 § 5.[1] In practice, this means that the affected individual or organisation must usually submit a formal request for prosecution.


What prosecutors examine in computer intrusion cases

In an unauthorised access investigation, prosecutors generally assess the technical evidence together with the business and contractual context. The fact that a person previously had access to a system does not automatically mean that access remained lawful.

Relevant evidence may include:

  • system, server, VPN and application logs;
  • authentication records and IP address data;
  • employment contracts, IT policies and access-management procedures;
  • authorisations granted to employees, suppliers or external consultants;
  • messages concerning the scope of work or the purpose of access;
  • forensic copies of devices, accounts and cloud environments;
  • evidence of copied, modified, encrypted or exfiltrated data.

A cyber attack may therefore create both criminal and operational consequences. A company may need to secure evidence, maintain business continuity, assess data-protection implications, notify insurers, and decide whether to make a criminal complaint. Delayed action can result in loss of log data and weaken the ability to identify the person responsible.


Three situations that may exclude unauthorised access

Polish law does not provide a universal list of “hacking exceptions.” Whether access was authorised depends on the facts. However, three situations are particularly important when assessing whether Article 267 may apply.

1. Clear consent from the authorised system owner or administrator

Access is not unauthorised where valid permission was granted by a person entitled to manage the system or the relevant data. Consent should define who may access the system, which accounts or environments are covered, and for what purpose. General permission to use company IT resources does not necessarily authorise access to HR records, financial systems or confidential customer databases.

2. Access based on statutory powers and procedural rules

Public authorities may access data or systems only where a specific legal basis and applicable procedural requirements exist. The assessment depends on the authority involved, the type of data, and the measures used. Lawful investigative activity should not be confused with private monitoring, unauthorised surveillance or informal access to another person’s account.

3. Access to information made genuinely public

Viewing information intentionally published without access restrictions is different from entering a protected system. However, publicly available content does not permit access to hidden panels, databases, source environments, administrative functions or technical resources that are not intended for public use. The boundary may be fact-sensitive, particularly where a website contains misconfigured but non-public resources.


Related cybercrime offences in Poland

Unauthorised access may be accompanied by other offences. Article 268a concerns destroying, damaging, deleting, altering or obstructing access to computer data. Article 269a addresses serious interference with an information system or network, including conduct that significantly disrupts operations. Article 269b criminalises the production, acquisition, sale or provision of devices or software adapted to commit certain computer offences.[1]

If access is used to obtain a financial benefit or cause financial loss through interference with data processing, Article 287 on computer fraud may also be relevant. Where personal data are involved, the company must separately assess obligations under the General Data Protection Regulation, including whether a personal data breach requires notification to the supervisory authority or affected individuals.[2]


Business response to suspected hacking or unauthorised access

An organisation should avoid immediately deleting accounts, devices or logs without preserving evidence. Containment is necessary, but evidence preservation is equally important for internal proceedings, insurance claims and possible criminal action.

  1. Secure logs, devices, access records and relevant communications.
  2. Limit access and reset credentials where continued intrusion is possible.
  3. Establish the scope of accessed systems, data and business impact.
  4. Review contracts, permissions and internal IT policies.
  5. Assess whether notification duties arise under data-protection or sectoral rules.
  6. Consider filing a motion for prosecution and supporting it with preserved evidence.

In complex cases, legal analysis should be coordinated with digital forensics. Kopeć & Zaborowski (KKZ) supports businesses in criminal-law assessments, crisis response, internal investigations and matters involving cybercrime. This is informational material, not legal advice.


For criminal cases concerning hacking or other cybercrime, it may be useful to consult the matter with a lawyer, obtain an assessment of the situation and discuss possible steps. Early analysis may be important where evidence is digital, volatile or subject to confidentiality obligations.


FAQ – Hacking Charges in Poland

Is hacking a separate criminal offence in Poland?

No. “Hacking” is a common term. Unauthorised system access is usually assessed under Article 267 of the Polish Penal Code, although other provisions may apply depending on the conduct and consequences.

Can an employee face hacking charges for accessing company systems?

Yes. An employee may face criminal risk if access exceeds granted permissions, concerns systems outside the employee’s role, or continues after employment or authorisation ends.

Is using another person’s password a criminal offence?

It may be. Using another person’s credentials without authorisation can constitute unauthorised access, particularly if it enables entry into a protected system or access to information not intended for that person.

Does copying data have to occur for Article 267 to apply?

No. Under Article 267 § 2, gaining unauthorised access to all or part of an information system may itself be sufficient. Copying, deleting or publishing data can lead to additional liability.

Can a company report a former employee for unauthorised access?

Yes, if evidence indicates that the former employee accessed company systems after permissions were withdrawn or used retained credentials without authority. Logs, offboarding records and access-control documentation are particularly relevant.

Is penetration testing legal in Poland?

It can be legal if carried out under clear authorisation. A written agreement should define the systems, dates, methods, permitted testing activities, reporting process and emergency contacts. Testing outside the agreed scope may create criminal risk.


Bibliography

  • [1] Act of 6 June 1997 – Penal Code (Poland), in particular Articles 267, 268a, 269a, 269b and 287, consolidated text available through the Internet System of Legal Acts (ISAP).
  • [2] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – General Data Protection Regulation, in particular Articles 33 and 34.
  • [3] Convention on Cybercrime, Budapest, 23 November 2001, Council of Europe Treaty Series No. 185.

Need help?

Maciej Zaborowski

Advocate, Managing Partner

contact@kkz.com.pl

+48 509 211 000

Expert advice

Surveillance and Wiretapping in Poland: Defense Strategies

Read more
Surveillance and Wiretapping in Poland: Defense Strategies

SIM Swapping and Phone Fraud in Poland: Criminal Threat

Read more
SIM Swapping and Phone Fraud in Poland: Criminal Threat

Digital Evidence in Polish Criminal Cases: Admissibility

Read more
Digital Evidence in Polish Criminal Cases: Admissibility
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm