• en
  • zh
  • ru
  • es
  • What we do
  • Who we work for
  • Experience
  • Awards
  • Team
  • Expert advice
  • Guidelines
  • Contact
  • en
  • zh
  • ru
  • es

Expert advice

Reporting Cybercrime in Poland: Step-by-Step for Victims

17.09.2026

Cybercrime is conduct committed through, against, or with the use of information systems, data, online accounts, networks, or electronic communications that may constitute a criminal offence. It includes, for example, account takeovers, phishing, ransomware, online fraud, unlawful access to systems, data theft, and disruption of IT services.

Reporting cybercrime in Poland requires prompt action. The first hours after an incident can determine whether funds can be frozen, logs can be secured, fraudulent accounts can be identified, and business disruption can be limited. For companies, delayed reporting may also increase financial losses, regulatory exposure, and reputational risk.

This is informational material, not legal advice. The appropriate reporting route and legal assessment depend on the facts, the location of the victim and perpetrator, the systems involved, and the available evidence.


When does a cyber incident become a criminal matter?

Not every IT incident is automatically a crime. A technical failure, contractual dispute with an IT supplier, or accidental disclosure of data may require internal, civil, employment, or regulatory action rather than a criminal complaint.

A criminal-law assessment should be considered where there are indications of intentional conduct, including:

  • unauthorised access to an email account, server, cloud environment, or business system;
  • interception of communications or theft of login credentials;
  • deletion, alteration, blocking, or destruction of data;
  • ransomware, malware, or a denial-of-service attack;
  • invoice fraud, CEO fraud, phishing, fake online shops, or payment-card fraud;
  • identity theft or use of another person’s data to obtain financing, goods, or services;
  • publication of confidential information, private correspondence, or unlawfully obtained materials.

Depending on the conduct, relevant provisions may include Articles 267, 268, 269, 269a, 286, 287 and 190a § 2 of the Polish Criminal Code. The classification is always dependent on the specific facts and available evidence. [1]


Reporting cybercrime in Poland: immediate steps for victims

1. Stop further damage without destroying evidence

Secure affected accounts and systems. Change passwords from a trusted device, revoke active sessions, enable multi-factor authentication, and block compromised payment cards or bank access. A company should involve its IT security team and preserve the original environment where possible.

Do not delete suspicious emails, chat messages, browser history, transaction confirmations, or system logs. Avoid reinstalling devices or wiping systems before relevant evidence has been copied and documented. Where ransomware or a serious intrusion is suspected, disconnect affected devices from the network if this can be done safely, but do not switch them off without considering the possible loss of volatile evidence.

2. Contact the bank or payment provider

Where fraud involves a transfer, card payment, online wallet, or cryptocurrency transaction, contact the financial institution immediately. Request a payment recall, account block, chargeback assessment where applicable, and preservation of transaction data.

A report to a bank is not a substitute for reporting a crime. It is, however, often the fastest practical step in a fraud case. The victim should obtain written confirmation of the report, the transaction reference number, and the bank’s response.

3. Prepare a clear evidence package

A criminal complaint is more effective when it identifies what happened, when it happened, how the victim became aware of it, and what loss or risk resulted. The following materials are usually useful:

  • a chronological description of events;
  • screenshots showing full URLs, dates, usernames, and payment details;
  • original emails with full headers, if available;
  • copies of invoices, contracts, bank confirmations, and correspondence;
  • IP addresses, server logs, access logs, and audit trails;
  • information about affected systems, accounts, devices, and users;
  • an initial calculation of financial loss and operational impact.

For businesses, evidence preservation should be coordinated with internal IT, compliance, HR, and management functions. Access to the evidence should be limited and documented to reduce the risk of alteration or disclosure.


How to report fraud or other cybercrime to the police or prosecutor

In Poland, a notification of a suspected offence may be submitted to the Police or to a public prosecutor. It may be made orally for the record or in writing. The notification should identify the reporting person, describe the facts, attach available evidence, and state whether the victim seeks to act as an injured party in the proceedings.

There is no requirement to identify the perpetrator before making a report. In cybercrime cases, the offender is frequently unknown at the initial stage. The key issue is to provide concrete facts that may allow the authorities to secure evidence from banks, hosting providers, telecommunications operators, platforms, or other entities.

The Police, including specialised cyber police units such as the Centralne Biuro Zwalczania Cyberprzestępczości, may investigate cyber-enabled offences. A victim may report the matter at a Police unit or directly to a prosecutor’s office. If there is an immediate threat to life, health, or safety, emergency services should be contacted through 112.

Under Article 304 § 1 of the Code of Criminal Procedure, anyone who learns of an offence prosecuted ex officio has a social duty to notify the prosecutor or Police. State and local-government institutions that learn of such an offence in connection with their activities have a legal duty to notify the authorities and secure evidence. [2]


Report the technical incident separately

A report to CERT Polska can be important where the incident concerns phishing, malicious domains, malware, or other cybersecurity threats. CERT Polska operates an incident-reporting service and accepts reports of suspicious SMS messages forwarded to 8080. [3]

A CERT report supports technical response and threat mitigation. It does not replace a criminal complaint to the Police or prosecutor. In a serious case, both steps may be appropriate.


What happens after a criminal complaint is filed?

The authorities may open an investigation, request additional documents, question the victim or witnesses, secure electronic evidence, and seek data from service providers. Cross-border cases can take longer because evidence may be held outside Poland and require international cooperation.

If the prosecutor or Police refuse to initiate proceedings or discontinue an investigation, the injured party may generally file a complaint against that decision. Article 306 of the Code of Criminal Procedure regulates this remedy, while the standard deadline for filing a complaint is seven days from service of the decision, subject to the circumstances of the case. [2]

A company should also consider parallel measures, including civil claims, contractual notices, insurance notification, data-protection analysis, employee measures, and communications management. Criminal proceedings do not automatically resolve all business consequences of a cyber incident.


Why legal coordination matters in corporate cybercrime cases

Cyber incidents often create several legal risks at the same time. A poorly drafted report can omit important facts, reveal confidential information unnecessarily, or make later recovery efforts more difficult. Internal investigations must also be conducted carefully where employees, contractors, or management members may be involved.

Kopeć & Zaborowski (KKZ) supports victims of economic and cybercrime in assessing criminal-law risks, preparing notifications, securing evidence, and coordinating legal steps with internal investigations and crisis-management processes.


In cybercrime matters, it may be appropriate to consult the case with a lawyer and discuss possible procedural steps. Early legal assessment can help clarify the available options and evidence requirements.


FAQ – Reporting Cybercrime in Poland

Can cybercrime be reported in Poland if the offender is unknown?

Yes. Most cybercrime reports are filed against an unknown perpetrator. The report should provide all available information about the account, website, email address, transaction, device, or communication used in the incident.

How can a victim report online fraud in Poland?

Online fraud may be reported to the Police or a prosecutor’s office. The victim should also contact the bank or payment provider immediately and preserve payment confirmations, messages, screenshots, and account details.

Is reporting phishing to CERT Polska enough?

No. CERT Polska reporting can support technical mitigation, such as blocking a phishing domain. A criminal complaint should be filed with the Police or prosecutor if the incident involves fraud, theft, unauthorised access, or another suspected offence.

What evidence is needed for a cybercrime complaint?

Useful evidence includes original emails, screenshots, bank records, system logs, IP addresses, contracts, chat records, and a timeline of events. Evidence should be preserved in its original form where possible.

Can a company report cybercrime in Poland?

Yes. A company may submit a notification through an authorised representative. The report should clearly identify the company, affected systems, financial loss, relevant employees or contractors, and available electronic evidence.

What can be done if the Police discontinue a cybercrime case?

An injured party may generally file a complaint against a decision refusing to initiate or discontinuing proceedings. The legal basis is Article 306 of the Code of Criminal Procedure, and the applicable deadline should be checked immediately after receiving the decision.


Bibliography

  • [1] Act of 6 June 1997 – Criminal Code, consolidated text: Journal of Laws of 2025, item 383, in particular Articles 267, 268, 269, 269a, 286, 287 and 190a § 2.
  • [2] Act of 6 June 1997 – Code of Criminal Procedure, consolidated text: Journal of Laws of 2025, item 46, in particular Articles 304, 306 and 460.
  • [3] CERT Polska, “Report an incident”, https://incydent.cert.pl/ (accessed 2025).

Need help?

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

contact@kkz.com.pl

+48 509 211 000

Expert advice

Surveillance and Wiretapping in Poland: Defense Strategies

Read more
Surveillance and Wiretapping in Poland: Defense Strategies

SIM Swapping and Phone Fraud in Poland: Criminal Threat

Read more
SIM Swapping and Phone Fraud in Poland: Criminal Threat

Digital Evidence in Polish Criminal Cases: Admissibility

Read more
Digital Evidence in Polish Criminal Cases: Admissibility
See all Expert advice

How can
we help you?

Contact
the experts
Maciej Zaborowski

Maciej Zaborowski

Advocate, Managing Partner

Paweł Gołębiewski

Paweł Gołębiewski

Attorney-at-law, Head of International Criminal Law Practice

Menu

  • What we do
  • Who we work for
  • Team
  • Experience
  • Awards
  • Expert advice
  • Glossary
  • Guidelines
  • RODO & terms of service
  • Contact
Kancelaria Kopeć Zaborowski Adwokaci i Radcowie Prawni

What we do

  • Expert’s Report on Conditions in the Polish Justice System (Expert Witness)
  • Driving under the influence in Poland
  • Asset recovery in Poland
  • Cybercrime in Poland
  • Extradition in Poland
  • Show more +
  • White-collar crime in Poland
  • Whistleblowers in Poland
  • Letter of safe conduct in Poland
  • Intellectual property protection in Poland
  • Insurance Fraud in Poland
  • European Arrest Warrant in Poland
  • Criminal defense in Poland
  • Red Notice in Poland
  • Interpol in Poland
  • Frauds in Poland
  • Investigative audits and internal investigations in Poland
  • Criminal compliance in Poland
  • Corporate crimes in Poland
  • Money Laundering in Poland
  • Scams in Poland
  • Corruption in Poland
  • VAT Refund Fraud in Poland
  • Organaized Crime in Poland
  • Insider trading and disclosure of inside information in Poland
  • Criminal liability of company officers in Poland
  • Capital Fraud in Poland

Our other services: + Kopeć & Zaborowski + Lawyers in Poland + Kontrola celno-skarbowa + Blokada Konta + ESG w Firmie + Kontrola PIP

Created by Tomczak | Stanisławski

© Copyrights to Kopeć & Zaborowski Law Firm