Incident

Coordinated cyberattacks disrupt polish payment infrastructure and travel services


Learn More

On November 1-2, 2025, Polish financial authorities and digital infrastructure were hit by a coordinated series of cyberattacks that temporarily disrupted national services. 

Early Saturday morning, Poland's national payment infrastructure experienced a significant DDoS attack that temporarily disrupted the BLIK mobile payment system, which serves approximately 17 million active users across the country. The attack was confirmed by Poland's Deputy Prime Minister and Minister of Digitalization, Krzysztof Gawkowski, who reported that intensive measures were immediately deployed to mitigate the effects. The BLIK system experienced service disruptions that prevented users from completing mobile payment transactions.

By 10:33 AM, BLIK operators reported that services were returning to normal. The number of affected individuals in the BLIK attack is not disclosed or whether any data was exposed.

After the payment infrastructure disruption, authorities reported that Warsaw-based travel company ITAKA had experienced a separate cyberattack, which was detected on Thursday, October 30, 2025. The breach resulted in unauthorized access to customer data from the company's "Client Zone" portal. According to official communications from ITAKA (Nowa Itaka sp. z o.o.), attackers gained access to portions of customer personal data. The company confirmed that approximately 10,000 user accounts were compromised, but indicated the scale of the breach could potentially be larger as investigations continued.

The exposed data from the ITAKA breach includes:

  • Full names
  • Email addresses
  • Phone numbers

ITAKA closed access to the Client Zone and started an investigation with specialists from Poland's NASK cybersecurity agency and law enforcement services. According to unofficial sources cited by Polish media outlet RMF FM, initial evidence suggests potential Russian involvement in the ITAKA attack.

It's not clear whether the two attacks are related. 

Coordinated cyberattacks disrupt polish payment infrastructure and travel services