Tuesday, September 8, 2026

News

AI Accelerates Attacks on Polish Universities, Experts Call for Joint Defense

PolandPatryk Raba
AI Accelerates Attacks on Polish Universities, Experts Call for Joint Defense
Fot. Maciej Talar / KSAF AGH, Wikimedia Commons (CC BY-SA 4.0)

CSIRT GOV recorded more than 23,000 IT security incident reports in 2025, a third more than the year before. Experts at the AGH Cybersecurity Center warn that AI isn't creating new types of attacks but is drastically increasing their scale and speed, leaving individual universities unable to defend themselves alone.

Contents
  1. The Scale of the Problem
  2. How AI Changes the Attack
  3. Joint Defense Instead of Lone Fortresses
  4. What's Next

Polish universities are facing a wave of AI-driven cyberattacks, and experts argue that the era of each institution defending itself alone is coming to an end. Data from CSIRT GOV shows that the number of reported IT security incidents is growing at a pace individual security teams struggle to keep up with.

Wojciech Górecki, a research specialist at the AGH Cybersecurity Center, stresses that artificial intelligence doesn't introduce qualitatively new attack methods, but radically changes the scale of the problem. Automation lets criminals prepare phishing campaigns faster, cheaper, and in more languages than just a few years ago.

The Scale of the Problem

A one-third year-on-year increase in reported incidents is one of the most striking figures to emerge in the debate over the security of Poland's academic sector in recent months. Universities process huge volumes of personal data belonging to students and staff, conduct research on strategically important technologies, and are increasingly targeted by attacks aimed not just at administrative systems but at research results themselves.

Górecki notes, however, that the rise in detected incidents alone doesn't necessarily mean the situation is only getting worse. It could also reflect the fact that monitoring and threat-detection systems at universities are maturing and catching more attack attempts than before, when some incidents simply went unnoticed.

How AI Changes the Attack

According to AGH experts, artificial intelligence has the strongest impact on social engineering, methods of manipulating people to extract data or system access. Language models make it possible to generate convincing, linguistically flawless phishing messages, automatically translate them into multiple languages, and distribute them at mass scale without human involvement at every stage of the campaign.

That means the barrier to entry for criminals is dropping, while the number of attack attempts security teams must face is growing faster than the resources those teams have available. A single university, even a technically well-equipped one, finds it increasingly hard to keep pace with the rate at which new attack variants are generated.

Artificial intelligence doesn't create entirely new categories of attacks, but it very significantly increases their scalability, speed and quality - Wojciech Górecki, AGH Cybersecurity Center

Joint Defense Instead of Lone Fortresses

The response proposed by the AGH Cybersecurity Center is to move away from a model in which each university tries to build a complete threat picture on its own and only reacts after an incident occurs. In its place should come a model of cooperation between academic institutions, based on efficient exchange of information about new attack methods and jointly building the resilience of the entire sector.

Cybersecurity is increasingly becoming a team sport - Wojciech Górecki, AGH Cybersecurity Center

The tool meant to make this possible is the European SOCCER project, coordinated by the AGH Cybersecurity Center. Its goal is to develop the capabilities of Security Operations Centers dedicated to the academic sector, teams responsible for round-the-clock monitoring of IT infrastructure and rapid response to detected threats.

What's Next

The topic is set to be explored further at the Cyber24Days conference, scheduled for October 7-8, 2026 at PGE Narodowy in Warsaw, where cybersecurity experts are expected to discuss, among other things, models of cooperation for the academic sector in the face of growing pressure from AI-assisted attacks.

For Polish universities, this means a practical shift in security investment priorities. Instead of solely expanding their own isolated defense systems, some of the funding and attention is meant to go toward building shared threat-information infrastructure, modeled on solutions already used in the banking and energy sectors.

Share: