Expert advice
Online Fraud and Internet Scams: Criminal Prosecution
06.09.2026
Online fraud is the intentional use of digital tools, false information or manipulation to cause another person to dispose of property to their detriment. In Poland, an internet scam may lead to criminal prosecution where the offender acts with the intention of obtaining financial benefit, unlawfully interferes with IT data or systems, or uses unlawfully obtained credentials.
The term online fraud Poland covers a wide range of conduct: fake online shops, phishing crime, marketplace scams, investment fraud, business email compromise, fraudulent payment links and unauthorised account access. The legal assessment depends on the method used, the offender’s intent, the financial loss and the available digital evidence.
Criminal offences used in online fraud cases in Poland
The most common legal basis for prosecuting an internet scam is Article 286 § 1 of the Polish Criminal Code. It applies where a person, acting to obtain financial benefit, causes another person to make an unfavourable disposition of property by misleading them, exploiting an error or exploiting an inability to properly understand the action taken. The statutory penalty is imprisonment from 6 months to 8 years.[1]
Typical examples include:
- creating a fake e-commerce store and accepting payments for goods never delivered;
- selling non-existent tickets, electronics, cars or rental services through online platforms;
- sending fraudulent invoices to a company after impersonating a supplier or management board member;
- inducing a victim to transfer funds to a supposed investment platform;
- using a false identity to obtain goods, loans or payment services.
Where the fraud concerns IT data, electronic payment instruments or interference with a computer system, other provisions may apply. Article 287 § 1 of the Criminal Code concerns computer fraud, including influencing automatic data processing or introducing, deleting or modifying computer data to obtain financial benefit or cause damage.[1]
Phishing crime may also involve unlawful access to information protected from unauthorised access. Depending on the facts, Article 267 of the Criminal Code may apply, particularly where an offender obtains credentials, intercepts communications or gains access to an IT system without authorisation.[1]
Not every failed transaction or delayed delivery constitutes criminal fraud. Criminal liability requires proof that the seller or service provider acted dishonestly from the outset, or that the conduct otherwise meets the statutory elements of an offence. A commercial dispute, poor performance of a contract or insolvency alone may require civil rather than criminal action.
How criminal prosecution of an internet scam begins
Criminal proceedings usually begin with a notification of a suspected offence submitted to the Police or the public prosecutor. The notification may be made in writing or orally for the record. It should identify the relevant events, dates, payment details, online accounts, communications and potential witnesses.
For businesses, speed is important. Digital evidence may be deleted, overwritten or retained by service providers only for limited periods. A company affected by e-commerce fraud or business email compromise should preserve evidence before changing systems, deleting emails or communicating extensively with the suspected offender.
Evidence in online fraud investigations
Digital evidence often determines whether an investigation can identify the offender and establish criminal intent. Useful materials may include:
- screenshots of advertisements, online store pages and social media profiles, with visible URLs and dates;
- email headers, message histories and records of fraudulent domains;
- bank transfer confirmations, card transaction data and cryptocurrency wallet addresses;
- order confirmations, invoices, delivery information and correspondence with platforms;
- server logs, access logs and internal IT security records;
- records of calls, where lawfully obtained and retained.
A screenshot alone may be insufficient where its origin or integrity is disputed. In more complex matters, IT forensic work may be required to secure devices, analyse metadata, reconstruct system activity or connect several accounts and transactions to the same person.
Phishing crime and business email compromise
Phishing is a method of obtaining passwords, payment data or authentication codes by impersonating a trusted organisation, employee, bank or online platform. A phishing attack may be directed at an individual, but the financial and operational consequences are often more serious for companies.
In business email compromise cases, the offender may impersonate a board member, finance director or supplier and request an urgent change of bank account details. The payment may be made by an employee who believes the instruction is genuine. Criminal prosecution may concern fraud, computer fraud, unlawful access to information and, in some cases, money laundering involving accounts used to receive and move the proceeds.[1][2]
From a management perspective, the response should include immediate contact with the bank, internal incident documentation, preservation of relevant mailboxes and logs, and an assessment of notification duties. Where personal data has been compromised, the controller may need to assess whether a breach notification to the President of the Personal Data Protection Office is required under Article 33 of the GDPR.[3]
E-commerce fraud: criminal and business consequences
E-commerce fraud may affect consumers, marketplaces, payment operators and legitimate online sellers. A fake shop can cause direct customer losses, while a fraudulent account operating on a marketplace can expose the platform and genuine business to complaints, chargebacks and reputational damage.
Companies should distinguish between a one-off customer complaint and indicators of organised fraud. Warning signs include multiple accounts using the same technical identifiers, unusual transaction patterns, repeated chargebacks, mismatched delivery data, rapid changes in payout accounts and coordinated use of stolen payment credentials.
For regulated entities and obliged institutions, fraud-related transactions may also trigger anti-money laundering analysis. The Act on Counteracting Money Laundering and Terrorist Financing requires obliged institutions to apply financial security measures and report justified suspicions to the General Inspector of Financial Information, subject to the statutory conditions.[2]
KKZ lawyers support businesses and individuals in matters involving scams, cybercrime and financial crime risk. The appropriate strategy depends on the evidence, the value of the loss, the location of the perpetrators and the need to protect business continuity.
Victim rights during criminal proceedings
A victim may submit evidence requests, seek access to case files within statutory limits, challenge certain decisions and apply for compensation. Under Article 46 of the Criminal Code, the court may impose an obligation to repair damage or compensate for harm. A victim may also pursue civil claims, although the choice of route should be assessed in light of recovery prospects, evidence and timing.[1]
In cross-border fraud cases, tracing funds and obtaining evidence from foreign providers may require international cooperation. The fact that a website, payment account or social media profile is registered abroad does not prevent proceedings in Poland, but it may affect the duration and complexity of the investigation.
This is informational material, not legal advice. The legal classification and available procedural measures depend on the facts of the individual case.
Anyone affected by online fraud, phishing or e-commerce fraud may consult the matter with a criminal lawyer and discuss possible procedural steps. Early assessment can help secure evidence and identify immediate measures concerning payments, systems and communications.
FAQ – Online Fraud and Internet Scams
Is online fraud a criminal offence in Poland?
Yes, where the conduct meets the statutory elements of fraud, computer fraud or another offence. Article 286 § 1 of the Criminal Code is commonly used where a victim is misled into making an unfavourable financial decision.
What should be reported after an internet scam?
A report should include payment confirmations, account numbers, screenshots, URLs, correspondence, phone numbers, delivery records and information about the suspected person or online account.
Can a bank reverse a fraudulent transfer?
It depends on the payment method, timing and circumstances. The bank should be contacted immediately. A criminal notification does not automatically reverse a transfer, but may support efforts to trace funds.
Is phishing always prosecuted as fraud?
Not always. Phishing may involve fraud, computer fraud, unlawful access to information or several offences at the same time, depending on how credentials were obtained and used.
Can a company report business email compromise to the Police?
Yes. The company should preserve emails, headers, logs, payment records and internal communications. Immediate action with the bank and IT security team is also important.
Can a victim recover money in criminal proceedings?
The court may order the offender to repair damage under Article 46 of the Criminal Code. Actual recovery depends on identifying the offender and locating recoverable assets.
Bibliography
- [1] Act of 6 June 1997 – Criminal Code (Journal of Laws 2025, item 383, as amended), in particular Articles 46, 267, 286 and 287.
- [2] Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing (Journal of Laws 2025, item 644, as amended).
- [3] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – General Data Protection Regulation, Article 33.
- [4] European Union Agency for Cybersecurity, ENISA Threat Landscape 2023, ENISA, 2023.
Need help?
Paweł Gołębiewski
Attorney-at-law, Head of International Criminal Law Practice
Expert advice
Surveillance and Wiretapping in Poland: Defense Strategies
Surveillance and Wiretapping in Poland: Defense StrategiesSIM Swapping and Phone Fraud in Poland: Criminal Threat
SIM Swapping and Phone Fraud in Poland: Criminal ThreatDigital Evidence in Polish Criminal Cases: Admissibility
Digital Evidence in Polish Criminal Cases: AdmissibilityHow can
we help you?
the experts