News
Cyberattacks on Polish Hospitals Rise Fastest in Years as AI Speeds Up Automated Intrusions
CSIRT CeZ recorded 1,441 security incidents at Polish medical facilities in 2025, up more than 40 percent from the year before. Experts say AI is accelerating attacks while modern AI-based protection covers only a few dozen of the country's 1,200-plus hospitals.
Contents
The number of cyberattacks on Polish hospitals and clinics is climbing at a pace the healthcare sector has never recorded before. According to CSIRT CeZ, the sectoral cybersecurity team of the Centre for e-Health (Centrum e-Zdrowia), medical facilities logged 1,441 security incidents in 2025, up from 1,028 a year earlier. That is a rise of more than 40 percent, and experts warn that advances in artificial intelligence are further speeding up and automating attacks, even as most hospitals still lack modern defensive tools.
The scale of the problem in numbers
Data from CSIRT CeZ, the official incident response team for the health sector, shows a trend that is hard to ignore. Over the course of a year, reported incidents rose from 1,028 to 1,441, and the first quarter of 2025 alone already exceeded the volume of all of 2023. A separate report from AMP S.A. states that from January to August 2025 alone there were 946 cyberattacks on medical facilities, compared with 632 in the same period of 2024 and fewer than 400 in 2021. Although the two datasets use different methodologies, the direction is the same: attacks are growing year over year at a double-digit rate.
Jeremi Olechnowicz, head of CSIRT CeZ, put it bluntly when commenting on the rising number of reports from medical facilities.
It's not a question of if, but when the next attack attempt will happen - Jeremi Olechnowicz, head of CSIRT CeZ
Szczecin and the March attack wave
Specific cases show just how long facilities take to recover from such incidents. The Independent Public Provincial Combined Hospital in Szczecin (Samodzielny Publiczny Wojewódzki Szpital Zespolony) fell victim to a serious attack, and three weeks later the hospital was still running in emergency mode. Registration for specialist clinics was suspended, and staff struggled to issue prescriptions and sick leave certificates. A spokesperson for the facility admitted that a full return to normal operations would take many more weeks.
It was one of four ransomware attacks that hit Polish healthcare in March 2026. Earlier victims included the Bonifraterskie Medical Center, where systems were restored within a few hours, and the "Eskulap" Medical Center in Racibórz. A similar scenario played out in Krakow, where a cyberattack paralyzed the hospital system to the point that the facility had to cancel scheduled surgeries.
Artificial intelligence on both sides
The advance of artificial intelligence is changing the nature of the threat. Generative models are increasingly used to build full attack chains, combining vulnerability analysis with automated exploitation, which shortens the time between a flaw being discovered and being exploited by criminals. AI also makes it easier to craft personalized phishing messages that are harder to distinguish from legitimate business correspondence, and experts warn the next stage could be fully autonomous models capable of running an entire attack without human involvement.
On the defensive side, however, artificial intelligence remains rare. Of the more than 1,200 hospitals operating in Poland, only a few dozen have modern, AI-supported security systems capable of, for example, continuously analyzing the behavior of medical devices connected to the network. Criminals know that facilities under the pressure of paralyzed systems are more likely to pay a ransom, which makes hospitals a particularly attractive target.
The human factor remains the weakest link
Despite the growing role of technology in attacks, experts stress that the biggest problem remains people, not infrastructure. Krzysztof Brud, president of Soflab Technology, estimates that as much as 80 percent of incidents in the health sector result from employee errors rather than technical failures or software vulnerabilities.
The biggest challenge today isn't technology, but the awareness and competence of staff and management - Krzysztof Brud, president of Soflab Technology
Brud is calling for mandatory cybersecurity training for medical staff and facility managers, arguing that even the best protection systems won't help if an employee opens an infected attachment or uses a weak password. That conclusion aligns with CSIRT CeZ data, which shows ransomware attacks account for more than half of reported incidents, sometimes resulting in complete loss of access to medical records, test results, and diagnostic systems.
What it means for patients and facilities
For Polish hospitals, the growing scale of attacks means rising costs, not just from ransoms but above all from operational downtime, canceled procedures, and weeks spent in emergency mode. For patients, what's at stake is the security of medical data, which ranks among the most expensive and sought-after on the black market because it combines health information with PESEL numbers (Poland's national ID number) and insurance details.
Government pledges of financial support and new security standards for the healthcare sector are still awaiting full implementation, and the pace of cybersecurity investment is not keeping up with the growing rate of attacks. The coming months will show whether facilities can build real resilience before AI on the criminals' side matches the pace of defense on the hospitals' side.

