Polish ABW Attributes Sejm DDoS to NoName057(16) as Retaliation for Russia Terrorism Designation, Warns of Escalating Hybrid Cyber Operations

Poland's Internal Security Agency (ABW) published an advisory on Poland's Special Services attributing a DDoS attack against the Polish parliament's website (sejm.gov.pl) to pro-Russian group NoName057(16), identifying the attack as direct retaliation for the Sejm's adoption of a resolution designating Russia as a state sponsor of terrorism. The CSIRT GOV team operating within ABW confirmed the unavailability was caused by NoName057(16) after the group published the parliamentary website as a target on Telegram — consistent with the group's documented pattern of geopolitically-triggered target selection.

Poland as a Primary Hybrid Warfare Target on NATO's Eastern Flank

ABW characterizes the escalating cyberattack campaign against Poland as part of Russia's broader hybrid warfare response to Polish military and political support for Ukraine. Targeted sectors include public administration, private companies, media outlets, energy infrastructure, and the defense industry. The ABW identifies three primary attack vectors: ransomware, DDoS, and phishing — each serving the overlapping objectives of destabilization, intimidation, and sowing public chaos. In parallel, the GhostWriter campaign — attributed to Russian state-linked operators — has been targeting email accounts and social media profiles of public figures across Central and Eastern European countries, with recent focus concentrated on Poland, aiming to seize information assets for disinformation operations.

Gov.pl Phishing Infrastructure: Fake Presidential Compensation Decree and Card Data Harvesting

In early December 2022, CSIRT GOV received intelligence about a phishing site impersonating the official gov.pl government domain. The fraudulent site claimed the President of Poland had signed a decree authorizing compensation payments financed through EU funds, directing visitors through a phishing flow to a fake payment card page under the pretext of a verification fee. ABW intervention resulted in the site being blocked. The operation combined financial fraud with personal data collection — a dual-purpose approach typical of Russian hybrid operations that simultaneously harvest intelligence and generate financial pressure on targets. In response to the overall threat escalation, the Polish Prime Minister activated the third-level cybersecurity alert CHARLIE-CRP.

Read the full analysis on IntelFusions