TrollEye Security

Cyber News

Poland’s Nuclear Research Centre Repels Cyberattack, Potential Iran Attribution

Poland's National Centre for Nuclear Research disclosed an attempted breach of its IT infrastructure, detected and blocked before any damage occurred, with early suspicion pointing to Iranian threat actors.

Iranian Threat Actors Suspected After Failed Attack on Polish Nuclear Facility

Poland’s National Centre for Nuclear Research (NCBJ) disclosed this week that hackers targeted its IT infrastructure in an attempted breach. The attack was detected and blocked before any damage was done, and the institute confirmed that operations continued without interruption.

In a statement released March 12, NCBJ Director Professor Jakub Kupecki confirmed that “the attack was thwarted, and the integrity of the systems was not compromised.” Security systems and internal response procedures caught the intrusion early, allowing IT teams to lock down affected infrastructure before it could be exploited. The MARIA reactor, Poland’s only operating nuclear reactor, used for scientific research, neutron studies, and medical isotope production, remained fully operational throughout the incident.

Iran in the Frame, But Investigators Are Cautious

NCBJ did not formally attribute the attack to any specific group or nation-state. However, Reuters reported that Polish investigators identified indicators suggesting Iranian involvement. Authorities are treating that attribution with caution, acknowledging that the signals could be false flags deliberately designed to mislead.

This is the latest in a run of cyber incidents against Polish infrastructure. In late December 2025, Russian threat group APT44, also known as Sandworm, attacked Poland’s power grid, hitting distributed energy resource sites, heat and power facilities, and wind and solar dispatch systems across roughly 30 locations.

A late-February report from the ICCT documented 31 confirmed hybrid warfare incidents attributed to Russian actors targeting Poland between mid-2025 and early 2026. The NCBJ incident suggests a second nation, Iran, may now be targeting Polish infrastructure, adding to the already significant Russian threat activity seen within a single quarter.

What This Means for Critical Infrastructure Security

Nuclear research facilities carry two things attackers want: sensitive technical data and symbolic value. A breach at an institution like NCBJ, even one that stops short of operational systems, generates headlines and signals vulnerability. That alone can be enough to serve an adversary’s goals.

The good news here is that early detection worked. NCBJ’s monitoring and response procedures caught the intrusion before it could move. That’s not luck, it’s what properly tuned detection looks like in practice.

The more pressing question is whether most organizations in similarly sensitive sectors have the same level of visibility. Intrusions in critical infrastructure environments often go undetected for weeks or months, by which point the damage is already done.

What to Do Next

The NCBJ incident is a useful reminder that nation-state actors target far more than governments and defense contractors. Any organization with geopolitical, scientific, or critical infrastructure relevance is a potential target, and most won’t know they’ve been infiltrated until it’s too late.

The question isn’t whether your organization could be targeted. It’s whether you’d detect it in time. Now is the moment to assess your visibility, harden your detection capabilities, and ensure your response plan is ready before you need it.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated