Data Leak Exposes Information of Hundreds of Soldiers From Key Military Unit. Army Calls It an “Incident”

Just days after the disclosure of a hack into a soldier’s official email account, reports have emerged of another serious security incident involving the Polish Armed Forces. According to findings by Onet, the personal data of 392 service members from the Communications and Information Technology Training Centre in Zegrze was stored on a OneDrive folder accessible to users within the unit’s internal network.

Soldier’s Email Account Compromised and Used in Further Attacks

The Cyber Defence Forces had previously announced that an official, unclassified email account belonging to a member of the Polish Armed Forces had been accessed without authorization. In its statement, the military said the attacker used “a targeted social engineering operation aimed at a specific user.”

The military stressed that no classified information was processed through the compromised account. However, the attacker gained access to official correspondence and then used the hijacked mailbox to carry out additional operations.

Phishing emails were sent from the soldier’s account to organizations operating both in Poland and abroad. Cybersecurity teams at the targeted organizations were notified of the threat.

The military command stated that the secured digital evidence had been analyzed. Authorities also launched efforts to determine the cause of the incident and prevent similar situations in the future.

Personal Data of 392 Soldiers Exposed

Onet also reported another case involving information security within the military. According to the outlet’s findings, a OneDrive folder accessible to users on the network of the Communications and Information Technology Training Centre contained personal data belonging to 392 soldiers.

The files reportedly included names, PESEL identification numbers, and information regarding the amount of benefits received by the service members. Anyone with access to the unit’s internal network could reportedly view and copy the documents. No evidence has been presented indicating that the data was actually removed from the military unit or obtained by foreign intelligence services.

The Communications and Information Technology Training Centre in Zegrze is the only institution within the Polish Armed Forces providing comprehensive specialist training in military communications, information technology, command systems, cybersecurity, and electronic warfare.

Territorial Defence Force Soldier Allegedly Shared the Files

According to Onet’s sources, the data was uploaded by a soldier from the Territorial Defence Forces who had been assigned to work in the centre’s Economic Section. The documents were allegedly made accessible to all users of the unit’s network due to human error or improper access configuration.

The leak was reportedly discovered by a civilian employee responsible for ensuring compliance with personal data protection regulations. The incident was reported to the Territorial Defence Forces Command, which oversees the training centre in Zegrze. According to Onet, the command subsequently notified Poland’s Inspector General for Personal Data Protection.

Initially, the incident was documented only in an internal service note, and no broader action was taken. The case reportedly gained momentum after intervention by the Territorial Defence Forces Command and after journalists submitted questions to the military unit.

Investigation Continues

According to Onet, the only person who has so far faced consequences is the soldier who uploaded the documents to the OneDrive folder. He reportedly received an official reprimand. No disciplinary action has been taken against those responsible for supervising the data.

The Communications and Information Technology Training Centre stated, however, that an internal investigation into the incident remains ongoing.

More in section

3,192FansLike
406FollowersFollow
2,001FollowersFollow

Latest