LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Phished Data via CERT Poland Data Breach (2023)

HIGH severityConfirmedHow we verify

Phished Data via CERT Poland Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·February 25, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Phished Data via CERT Poland Data Breach (2023)

Reported February 25, 2023. Approximately 68K people affected.

HIGH
Severity
68K
People affected
2
Data types exposed
February 25, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Phished Data via CERT Poland Data Breach (2023) (reported February 25, 2023) exposed Email addresses and Passwords belonging to roughly 68K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Account credentials exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Phished Data via CERT Poland Data Breach (2023) breach?
68K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In August 2023, CERT Poland observed a phishing campaign that collected credentials from approximately 68,000 victims. The campaign gathered email addresses and passwords through messages designed to look like purchase-order confirmations. Public reporting associated with this incident lists a report date of February 25, 2023, and identifies the exposed data types as email addresses and passwords. CERT Poland also identified 202 other phishing campaigns operating on the same command-and-control server; that server has since been dismantled.

The episode matters because stolen login credentials remain one of the most direct routes to account takeover, secondary fraud, and further phishing. What is known so far comes from CERT Poland’s observation of the campaign rather than from a disclosed breach of a single named commercial service; exact timing of individual victim compromises and the full downstream use of the harvested data remain limited in public detail.

What happened

According to the reported summary, CERT Poland detected a phishing operation in August 2023 that successfully collected credentials from 68,000 people. The lure was a phishing email that masqueraded as a purchase-order confirmation. Victims who interacted with it supplied email addresses and passwords. Investigators linked the same command-and-control infrastructure to an additional 202 phishing campaigns. That server has now been taken down. No further public figures have been released on the precise start or end dates of credential collection, the geographic distribution of victims, or any subsequent sale or reuse of the data set. The incident is therefore documented primarily through CERT Poland’s observation and the dismantling of the shared infrastructure rather than through a corporate breach notification from a single affected brand.

How a breach like this happens

Credential-harvesting phishing campaigns typically begin with large-scale distribution of emails that imitate a familiar business process—an order confirmation, an invoice, or a shipping notice. The message contains a link or attachment that leads to a counterfeit login page controlled by the attackers. When a recipient enters an email address and password, those details are captured and stored on the attackers’ server. The same infrastructure is often reused across many themed campaigns, which is why the discovery of one active lure can reveal dozens or hundreds of related operations. Once credentials are collected, they may be tested against popular web services, used to reset other accounts, or packaged for later sale. Dismantling the command-and-control server interrupts the collection pipeline, but it does not automatically erase data already obtained. No specific threat group has been publicly attributed to this particular set of campaigns in the available facts.

About Phished Data via CERT Poland

CERT Poland is Poland’s national computer emergency response team. Organisations of this type monitor, analyse and publicly warn about cyber threats affecting citizens, businesses and public institutions within their jurisdiction. They routinely track phishing infrastructure, sinkhole malicious domains, and publish indicators so that defenders and the public can recognise active scams. The data set described here is therefore not the result of a compromise of CERT Poland’s own systems; it is a collection of credentials harvested by criminals and observed by the CERT during its defensive work. Because a national CERT sits at the intersection of threat intelligence and public warning, its findings often surface large volumes of phished credentials that would otherwise remain invisible until individual victims notice account misuse. The consequential aspect is the scale: tens of thousands of email-and-password pairs gathered under a single campaign theme, plus evidence of many parallel campaigns sharing the same backend.

The information in question

The facts name two data types as exposed: email addresses and passwords. No other categories—such as names, phone numbers, financial account details or government identifiers—are listed in the available record. Organisations and campaigns of this kind typically aim only for login credentials, because those can be reused immediately. Exact file formats, whether passwords were stored in plain text or hashed, and whether any additional metadata accompanied the credentials are not disclosed. Readers should treat the confirmed exposure as limited to the email-and-password pairs collected by the purchase-order phishing lure and any related campaigns on the same server, while recognising that public detail beyond those two fields is unconfirmed.

What's at stake

For affected individuals the primary risk is account takeover. An email address paired with a password that is reused on other sites can give an attacker access to webmail, social media, shopping accounts or cloud storage. From a compromised mailbox an attacker can often reset passwords elsewhere, intercept one-time codes, or launch convincing follow-on phishing against the victim’s contacts. Financial loss, identity misuse and reputational harm can follow, though the severity depends on password reuse and the sensitivity of the accounts involved. For the broader ecosystem, the existence of 202 additional campaigns on the same infrastructure illustrates how a single backend can support many simultaneous lures, amplifying the total number of people at risk until the server is removed. The dismantling of that server reduces ongoing collection but does not reverse harm already done to those whose credentials were captured.

If your data was in this breach

If you believe you may have interacted with a purchase-order confirmation email around the period of this campaign, change the password on the affected email account and on any other service where you used the same password. Enable multi-factor authentication wherever it is offered. Monitor account activity for unexpected logins or password-reset messages. Be alert to follow-up phishing that references orders you never placed. Because credential dumps frequently circulate after collection, you can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets and to receive guidance on next steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyPhished Data via CERT Poland security record
74/100
DoxxScan™ · Moderate doxx risk
B- 78Above-average record

1 reported incident on record.

See Phished Data via CERT Poland’s full breach history →

More recent breaches

Hathway Data Breach (2023)December 17, 2023InflateVids Data Breach (2023)December 12, 2023KitchenPal Data Breach (2023)November 14, 2023Facebook Marketplace Data Breach (2023)October 1, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Phished Data via CERT Poland Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram