{"id":6334,"date":"2026-07-17T08:47:44","date_gmt":"2026-07-17T08:47:44","guid":{"rendered":"https:\/\/ceo.com.pl\/en\/?p=6334"},"modified":"2026-07-17T08:47:44","modified_gmt":"2026-07-17T08:47:44","slug":"poland-among-the-worlds-top-cyberthreat-targets-93091","status":"publish","type":"post","link":"https:\/\/ceo.com.pl\/en\/poland-among-the-worlds-top-cyberthreat-targets-93091\/","title":{"rendered":"Poland Among the World\u2019s Top Cyberthreat Targets"},"content":{"rendered":"<p><strong>Poland ranked first worldwide for detections of downloaders, which retrieve additional threats, and CloudEye, a tool used to conceal and deliver malware.\u00a0The country also ranked second for email-borne threats and among the targets of web-based threats.<\/strong><\/p>\n<p>ESET analysed nearly 900,000 add-ons and instruction sets for AI agents. More than 25,000 were classified as suspicious, while over 3,000 were identified as malicious.<\/p>\n<p>During the first half of the year, Poland ranked among the world\u2019s leading countries for detections of multiple types of cyberthreats recorded by ESET systems. It placed first for downloader detections, involving malicious programs designed to download additional threats onto a device, as well as for detections of CloudEye, a tool used by cybercriminals to conceal and distribute malware.<\/p>\n<p>Poland also ranked second for email threats and among the targets of web-based threats, as well as third for ransomware and attacks targeting Remote Desktop Protocol services.<\/p>\n<p>At the same time, the latest <strong>ESET Threat Report H1 2026<\/strong> shows that cybercriminals are increasingly improving the effectiveness of established attack methods by adapting them to new platforms, cloud services and users\u2019 growing trust in artificial intelligence.<\/p>\n<p>The report covers the period from December 2025 to May 2026. One of its most important conclusions is the growing role of AI, both for users and businesses and for cybercriminals.<\/p>\n<p>ESET analysed nearly 900,000 so-called AI skills: small add-ons or sets of instructions defining which tasks an AI agent can perform, which tools it should use and which data it can access. More than 25,000 were classified as suspicious, while over 3,000 were identified as clearly malicious.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_85 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/ceo.com.pl\/en\/poland-among-the-worlds-top-cyberthreat-targets-93091\/#Poland_in_the_crosshairs_among_the_worlds_most_heavily_targeted_countries\" >Poland in the crosshairs: among the world\u2019s most heavily targeted countries<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/ceo.com.pl\/en\/poland-among-the-worlds-top-cyberthreat-targets-93091\/#Artificial_intelligence_is_also_creating_new_opportunities_for_cybercriminals\" >Artificial intelligence is also creating new opportunities for cybercriminals<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/ceo.com.pl\/en\/poland-among-the-worlds-top-cyberthreat-targets-93091\/#Fake_messages_real_attacks_social_engineering_in_a_new_form\" >Fake messages, real attacks: social engineering in a new form<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/ceo.com.pl\/en\/poland-among-the-worlds-top-cyberthreat-targets-93091\/#QR_codes_are_increasingly_leading_users_into_traps\" >QR codes are increasingly leading users into traps<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/ceo.com.pl\/en\/poland-among-the-worlds-top-cyberthreat-targets-93091\/#Ransomware_continues_to_grow_although_fewer_victims_are_paying\" >Ransomware continues to grow, although fewer victims are paying<\/a><\/li><\/ul><\/nav><\/div>\n<h2><span class=\"ez-toc-section\" id=\"Poland_in_the_crosshairs_among_the_worlds_most_heavily_targeted_countries\"><\/span>Poland in the crosshairs: among the world\u2019s most heavily targeted countries<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>According to ESET telemetry data, Poland ranked:<\/p>\n<ul>\n<li>First for downloader detections, ahead of Turkey and Italy.<\/li>\n<li>First for CloudEye detections, ahead of Turkey and Spain.<\/li>\n<li>Second for email threats, behind Japan.<\/li>\n<li>Second among the targets of web-based threats, behind Japan.<\/li>\n<li>Third for ransomware detections, behind Turkey and the United States.<\/li>\n<li>Third among the targets of attacks on RDP services, behind Spain and the United States.<\/li>\n<li>Fourth for infostealer detections, behind Turkey, Japan and Spain.<\/li>\n<\/ul>\n<p>Poland\u2019s high position is therefore not limited to one type of incident. It covers a broad range of threats, from attacks beginning in emails and on websites to information theft, ransomware and attempts to exploit remote-access services.<\/p>\n<p>Poland\u2019s first-place ranking for downloader detections is particularly significant. Downloaders are programs designed to retrieve further components of an attack, such as data-stealing tools, ransomware or software enabling attackers to take control of a system.<\/p>\n<p>Detecting a downloader may therefore indicate the beginning of a more extensive infection chain.<\/p>\n<p>In the case of ransomware, this is another six-month period in which Poland has ranked among the three most frequently targeted countries in the world. Malware that encrypts data and demands payment for restoring access has been one of the most serious threats in cyberspace for many years.<\/p>\n<p>Poland\u2019s high position in ransomware detection rankings is not solely the result of external threats. To a significant extent, it also reflects internal weaknesses among Polish companies.<\/p>\n<p>According to the <strong>Cybersecurity Profile of Polish Business 2026<\/strong> report prepared by ESET and DAGMA IT Security, only 17% of employees know what ransomware is. Meanwhile, half of Polish employees who use a computer at work have received no cybersecurity training during the past five years.<\/p>\n<p>\u201cThe consequences of failing to invest in cybersecurity can be calculated by estimating the cost of a successful attack. Building a protection strategy should therefore begin with a risk analysis: which attacks are most likely, and how much would the company lose if they occurred?<\/p>\n<p>\u201cA simple calculation combining the probability of a specific threat with the estimated cost of its consequences provides solid arguments during budget discussions. It is far more effective than referring only to regulations or general statistics.<\/p>\n<p>\u201cOnce the scale of the risk is understood, an organisation can rationally set its priorities, because it is impossible to secure everything at once. The key is to identify the most valuable assets and begin investments with those,\u201d explains Dawid Zi\u0119cina of DAGMA IT Security.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Artificial_intelligence_is_also_creating_new_opportunities_for_cybercriminals\"><\/span>Artificial intelligence is also creating new opportunities for cybercriminals<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The add-ons for AI agents analysed by ESET included components using offensive tools such as Mimikatz and Impacket, as well as self-modifying scripts whose behaviour can change after installation.<\/p>\n<p>Researchers also identified seemingly safe add-ons promoted as security scanners. In practice, some of them use only very basic analytical methods, creating a false sense of security among users.<\/p>\n<p>AI is also appearing directly within malicious software. ESET identified <strong>PromptSpy<\/strong>, the first known Android threat to actively use generative artificial intelligence while operating.<\/p>\n<p>The malware uses the Gemini model to interpret elements of the user interface and adapt its actions to different devices and environments. Such cases remain rare, but they demonstrate how AI may increase the flexibility of future cyberthreats.<\/p>\n<p>\u201cInstead of relying on completely new methods and tools, attackers are quickly adapting proven techniques to new platforms, technologies and user behaviours. The number of add-ons for AI agents is increasing rapidly, while also expanding the potential attack surface,\u201d adds Kamil Sadkowski.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Fake_messages_real_attacks_social_engineering_in_a_new_form\"><\/span>Fake messages, real attacks: social engineering in a new form<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>The ClickFix technique also continued to develop during the first half of 2026. Attackers display a fake error message or technical warning and then provide the user with supposedly simple instructions for resolving the problem.<\/p>\n<p>In reality, the victim is manipulated into manually executing a malicious command.<\/p>\n<p>The number of ClickFix detections increased by 108% between the second half of 2025 and the first half of 2026.<\/p>\n<p>New variants use websites containing instructions presented as AI-generated content, browser extensions and cloud-service login processes.<\/p>\n<p>In a variant known as ConsentFix, cybercriminals attempt to steal an authorisation token. In certain scenarios, this may allow them to access an account without entering the password again and without triggering an additional login confirmation.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"QR_codes_are_increasingly_leading_users_into_traps\"><\/span>QR codes are increasingly leading users into traps<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Phishing attacks using QR codes, known as quishing, also reached record levels.<\/p>\n<p>During the first half of 2026, approximately 11% of detected phishing emails contained a QR code. ESET systems recorded an average of around 100,000 such detections per month.<\/p>\n<p>Attackers use QR codes to conceal the destination address and move the interaction to a smartphone, where it is more difficult for users to verify the full website address.<\/p>\n<p>The popularity of QR codes in payments, restaurant menus and login systems means that many people scan them automatically without first checking their source.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Ransomware_continues_to_grow_although_fewer_victims_are_paying\"><\/span>Ransomware continues to grow, although fewer victims are paying<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>ESET documented more than 100 EDR killer tools designed to disable, freeze or blind security software before the main ransomware component is launched.<\/p>\n<p>More than 60 of these tools exploit vulnerable drivers to interfere with security mechanisms at the operating-system level.<\/p>\n<p>At the same time, despite the continued increase in ransomware attacks, the proportion of victims choosing to pay a ransom has reached a historic low.<\/p>\n<p>Industry reports analysed by ESET indicate that between 14% and 28% of affected organisations paid the ransom.<\/p>\n<p><em>Country rankings refer to detections recorded by ESET solutions and do not constitute a comprehensive ranking of all cyberattacks occurring worldwide.<\/em><\/p>\n<p>The full <strong>ESET Threat Report H1 2026<\/strong> contains detailed telemetry data, an analysis of emerging attack techniques and descriptions of the most significant threats recorded between December 2025 and May 2026.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Poland ranked first worldwide for detections of downloaders, which retrieve additional threats, and CloudEye, a tool used to conceal and deliver malware.\u00a0The country also ranked second for email-borne threats and among the targets of web-based threats. ESET analysed nearly 900,000 add-ons and instruction sets for AI agents. More than 25,000 were classified as suspicious, while [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5357,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","jetpack_publicize_message":"Poland has ranked among the world\u2019s most heavily targeted countries for cyberthreats.\r\n\r\nAccording to the latest ESET Threat Report H1 2026, Poland placed first worldwide for downloader and CloudEye detections, second for email and web-based threats, and third for ransomware and attacks on Remote Desktop Protocol services.\r\n\r\nThe report also highlights the growing role of artificial intelligence in cybercrime. ESET analysed nearly 900,000 AI skills and instruction sets for AI agents. More than 25,000 were classified as suspicious, while over 3,000 were identified as malicious.\r\n\r\nCybercriminals are also increasingly using ClickFix attacks, QR-code phishing and tools designed to disable security software before launching ransomware.\r\n\r\nRead more about the latest cyberthreat trends and why Poland remains high on attackers\u2019 target lists.\r\n\r\n#Cybersecurity #Poland #ESET #Ransomware #ArtificialIntelligence #CyberThreats #AI","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[3457],"tags":[2974,2838,2839,3626,284,4745,2935,64,2732,2937,2813,286],"class_list":["post-6334","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security","tag-artificial-intelligence","tag-cloud-services","tag-content","tag-eset","tag-italy","tag-kamil-sadkowski","tag-malware","tag-poland","tag-ranking","tag-ransomware","tag-sense","tag-spain"],"jetpack_publicize_connections":[],"_links":{"self":[{"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/posts\/6334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/comments?post=6334"}],"version-history":[{"count":0,"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/posts\/6334\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/media\/5357"}],"wp:attachment":[{"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/media?parent=6334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/categories?post=6334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ceo.com.pl\/en\/wp-json\/wp\/v2\/tags?post=6334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}