Expert advice
Ransomware Attacks: Criminal Liability in Poland
11.09.2026
Ransomware is malicious software that encrypts, blocks or exfiltrates data and then demands payment in exchange for restoring access, providing decryption tools or refraining from publishing stolen information. A ransomware attack may therefore combine unauthorised access to IT systems, interference with computer data, malware distribution and cyber extortion.
For businesses, the immediate consequences often include operational downtime, loss of data availability, contractual disruption, GDPR-related exposure and reputational damage. From a criminal-law perspective, the relevant conduct may involve several offences under the Polish Criminal Code, depending on the method of intrusion, the scale of damage and the role of each participant. Kopeć & Zaborowski (KKZ) advises businesses and individuals in criminal matters involving cybercrime, fraud and digital evidence.
Ransomware criminal liability in Poland
Polish law does not contain a separate offence labelled “ransomware attack”. Criminal liability is assessed through provisions addressing unlawful access to computer systems, damage to data, disruption of IT operations, extortion and the use of tools designed for cybercrime.
The legal classification depends on the facts. A person who merely gains access to a corporate network may be liable under different provisions than a person who deploys encryption malware, negotiates a ransom, launders cryptocurrency or publishes stolen files.
Key criminal offences linked to ransomware attacks
- Unauthorised access to information or systems – Article 267 of the Polish Criminal Code penalises, among other conduct, obtaining access to information not intended for the perpetrator by overcoming or bypassing security measures. It may apply where attackers use stolen credentials, exploit vulnerabilities or install remote-access tools without authorisation.
- Interference with computer data – Article 268a of the Criminal Code concerns destroying, damaging, deleting, altering or obstructing access to computer data without authorisation. This may cover the encryption of business files and databases.
- Disruption of an IT system or network – Article 269a penalises significant interference with the functioning of an ICT system, information system, data communications network or transmission of data. This provision is particularly relevant where ransomware prevents an enterprise, hospital, logistics operator or public authority from operating normally.
- Distribution of malware or cybercrime tools – Article 269b criminalises the production, acquisition, sale or making available of devices or computer programs adapted to commit specified cyber offences. Malware distribution may therefore create liability even where the distributor does not personally deploy ransomware against the final victim.
- Computer fraud – Article 287 may apply where a perpetrator influences automatic processing, collection or transmission of data in order to obtain a financial benefit or cause damage. The provision can be relevant to attacks involving manipulation of payment systems, account data or cryptocurrency transactions.
- Extortion – Article 282 covers forcing another person to dispose of property through violence or an unlawful threat. Ransom demands accompanied by threats to destroy data, continue disruption or disclose sensitive material require careful assessment under this provision and other potentially applicable rules.
Cyber extortion and double-extortion ransomware
Many current attacks involve “double extortion”. Attackers first copy data and then encrypt it. The ransom demand is supported by a threat to publish customer records, trade secrets, employee data or internal correspondence.
The legal consequences may be broader than in a case involving encryption alone. Publishing or threatening to publish data can create additional exposure related to privacy, business secrets, personal rights and, depending on the content, other criminal offences. The fact that a victim restores systems from backups does not necessarily end the criminal risk if stolen data remains in the attackers’ possession.
Liability of ransomware affiliates, negotiators and cryptocurrency intermediaries
Ransomware operations are frequently divided among several actors. One group develops malware, another obtains initial access, another communicates with victims, and another moves cryptocurrency through wallets, exchanges or mixing services.
Under Articles 18 and 19 of the Criminal Code, liability may extend to persons who incite, aid or facilitate an offence. A person does not need to deploy malware personally to face criminal allegations. The required mental element and the actual contribution to the offence remain crucial in each case.
Where funds derived from ransomware are concealed, transferred or converted to conceal their criminal origin, Article 299 of the Criminal Code on money laundering may also be relevant.
Paying a ransomware demand: three exceptions requiring legal assessment
Polish criminal law does not generally make a victim automatically criminally liable merely for paying a ransom to recover business operations. However, three exceptions require a case-specific legal assessment:
- Money laundering risk – liability under Article 299 may arise where a person knowingly participates in transactions intended to conceal the criminal origin of funds.
- Sanctions restrictions – a payment may be prohibited if it benefits a person or entity subject to applicable EU restrictive measures, including cyber-related sanctions under Council Regulation (EU) 2019/796.
- Terrorist financing concerns – financing or supporting terrorist activity may trigger liability under Article 165a of the Criminal Code where the statutory conditions are met.
Payment should therefore not be treated solely as an IT or commercial decision. It requires verification of available intelligence, the recipient’s identity where possible, sanctions exposure, reporting obligations and the evidence needed for law-enforcement proceedings.
Evidence preservation and reporting after a ransomware attack
Fast action affects both the investigation and the company’s ability to resume operations. Key evidence may include ransom notes, attacker communications, wallet addresses, logs, copies of affected systems, access records, malware samples and records of decisions taken during the incident.
Internal teams should avoid altering original data unnecessarily. Forensic work must be coordinated with incident response, insurance requirements, data protection obligations and potential notifications to authorities. A poorly documented response can make it more difficult to identify perpetrators, recover assets or demonstrate that management acted with appropriate diligence.
Ransomware cases often have an international dimension. Polish authorities may use cross-border cooperation mechanisms, including the Convention on Cybercrime, where infrastructure, cryptocurrency exchanges or perpetrators are located outside Poland.
Businesses affected by ransomware or suspected malware distribution may consult the matter with a lawyer to obtain an assessment of criminal-law risks and possible next steps. Further information on related proceedings is available in KKZ’s materials on cybercrime and cybercrime prosecution in Poland.
FAQ – Ransomware Attacks
Is ransomware illegal in Poland?
Yes. Although there is no single ransomware offence, deploying ransomware may constitute unlawful access, interference with computer data, disruption of IT systems, extortion, computer fraud or other offences under the Criminal Code.
Can malware distribution lead to criminal liability without an actual attack?
It can. Article 269b of the Criminal Code may apply to making available computer programs or tools adapted to commit specified cyber offences, subject to the facts and intent of the person involved.
Is a company criminally liable if it pays a ransomware ransom?
Payment does not automatically create criminal liability. However, sanctions, money-laundering and terrorist-financing risks must be assessed before any transfer is made.
What is double-extortion ransomware?
It is an attack in which perpetrators both encrypt systems and steal data. They then demand payment for decryption and for not disclosing the stolen information.
Can ransomware attackers be prosecuted if they operate outside Poland?
Potentially, yes. The investigation may involve international cooperation, digital evidence requests and cooperation with foreign law-enforcement authorities, depending on the location of perpetrators, victims and infrastructure.
What evidence should be secured after a ransomware attack?
Relevant material includes ransom notes, communications, system logs, access records, malware samples, wallet addresses, forensic images and records of internal decisions made during the incident.
Bibliography
- [1] Act of 6 June 1997 – Polish Criminal Code, consolidated text: Journal of Laws of 2024, item 17, as amended, in particular Articles 18, 19, 165a, 267, 268a, 269a, 269b, 282, 287 and 299.
- [2] Council Regulation (EU) 2019/796 of 17 May 2019 concerning restrictive measures against cyber-attacks threatening the Union or its Member States.
- [3] Convention on Cybercrime, Budapest, 23 November 2001, Council of Europe Treaty Series No. 185.
- [4] European Union Agency for Cybersecurity (ENISA), ENISA Threat Landscape 2024.
Need help?
Expert advice
Surveillance and Wiretapping in Poland: Defense Strategies
Surveillance and Wiretapping in Poland: Defense StrategiesSIM Swapping and Phone Fraud in Poland: Criminal Threat
SIM Swapping and Phone Fraud in Poland: Criminal ThreatDigital Evidence in Polish Criminal Cases: Admissibility
Digital Evidence in Polish Criminal Cases: AdmissibilityHow can
we help you?
the experts