Cyberattack Wave Hits State Institutions Across CEE and SEE

From Bosnia's border service to Poland's health records and Latvia's vehicle registry, a wave of cyberattacks has struck state institutions across CEE and SEE since June, exposing tens of millions of records.

Cyberattack Wave Hits State Institutions Across CEE and SEE
Photo: Illustration (AdriaDefense.com)

Government institutions and state-owned companies across Central and Eastern Europe and South-Eastern Europe have reported a series of cyberattacks in recent months, with incidents affecting health records, energy infrastructure, land registries, vehicle databases and migration systems.

Poland has faced some of the largest confirmed cases, including the theft of records associated with nearly 19 million people and a separate intrusion into a combined heat and power plant. Latvia, Romania, Croatia, Hungary, Bosnia and Herzegovina and Slovakia have also disclosed attacks on public-sector or critical systems.

Authorities have not presented evidence that the incidents form a coordinated campaign. Taken together, however, they show how attacks on civilian government networks can move beyond data theft and interfere with services ranging from property transactions to energy operations.

Poland faces health data breach and power plant intrusion

Poland disclosed two significant cyber incidents in August involving markedly different targets.

On August 12, Deputy Prime Minister and Minister of Digital Affairs Krzysztof Gawkowski confirmed that attackers had breached MyDr, an electronic medical records platform used by doctors and clinics.

The breach exposed records associated with nearly 19 million people and involved more than two terabytes of stolen data. Attackers demonstrated access to the information by releasing personal data belonging to a senior politician, including a national identification number, phone number and prescription history.

Polish officials assessed the attack as financially rather than politically motivated.

A separate case reached operational energy infrastructure. On August 8, Poland's national cybersecurity response team CERT Polska disclosed an intrusion into a combined heat and power plant supplying approximately 50,000 residents.

The attack took place in December 2025 through the private cellular network used by the local grid operator to communicate with remote equipment. Attackers shut down a steam turbine and the plant's water treatment system.

Operators began recovery while the attackers were still present in the network, but heat and electricity supplies to customers were not interrupted. It was the second confirmed cyberattack against a Polish combined heat and power plant since December 2025.

Latvia investigates breaches at road and forestry agencies

Latvia has dealt with two separate incidents involving state entities since June.

State forestry company Latvijas Valsts meži suffered a ransomware attack in mid-June. A group identifying itself as ByteToBreach exploited an unpatched GeoServer vulnerability, encrypted company systems and removed internal data.

The vulnerability had reportedly been known to the company for two years before the intrusion.

A second attack affected Latvia's Road Traffic Safety Directorate in early August. Investigators subsequently determined that attackers had accessed personal information belonging to approximately 1.2 million people.

The exposed information included national identification numbers, names, addresses, license plate numbers and payment records. Authorities said passwords were not compromised.

Latvia's Crisis Management Centre and national cybersecurity response organization CERT.lv established a dedicated group to coordinate the response. The government also ordered a broader examination of critical infrastructure cybersecurity following the incidents.

Romania land registry attack disrupts property transactions

Romania's National Agency for Cadastre and Real Estate Publicity took its e-Terra land registry platform offline on July 14 following an incident initially described as a technical failure.

Authorities later identified the incident as a ransomware attack. The attacker gained access using valid credentials and subsequently wiped the production database and backups after an extortion demand was not paid.

The consequences extended beyond the loss of data. Romania's real estate market was disrupted for approximately a week as notaries were unable to register transactions and citizens could not obtain documents proving ownership.

Days later, the same attacker was linked to a breach involving Hungary's State Treasury and its Agricultural and Rural Development Office.

Hungarian authorities said the intrusion did not destroy data. Portions of the stolen material subsequently appeared for sale on an underground forum.

Croatia investigates intrusions dating to April

Croatian police have been investigating a broader intrusion campaign against public-sector computer systems that began in early April 2026.

The Ministry of the Interior detected suspicious activity in mid-April. Institutions confirmed as affected include the Ministry of the Interior, Croatian Health Insurance Fund, Croatian Pension Insurance Institute, Tax Administration and Croatian Automobile Club.

Police arrested a Serbian national on Croatia's Adriatic coast on July 28 and later placed the suspect in pretrial detention over alleged unauthorized access to computer systems belonging to public bodies and other legal entities.

Investigators reportedly traced part of the activity to a cybersecurity company based in Novi Sad, Serbia.

Separately, a group identifying itself as INF Grupa claimed responsibility for defacing the website of Croatia's Ministry of Labour, Pension System, Family and Social Policy in May. In early August, the group also published a database it claimed originated from Croatia's judicial system.

Croatian authorities have not publicly established that those claims are connected to the suspect arrested in July. The extent of information compromised during the wider campaign also remains under investigation.

Bosnia investigates breach of migration service systems

Bosnia and Herzegovina's Service for Foreigners Affairs, an agency within the Ministry of Security responsible for migration controls and foreign nationals, confirmed on August 17 that domestic security agencies had notified it of an intrusion into its information technology systems.

According to the agency, the attacker obtained user credentials that were subsequently used to store and distribute stolen data. Authorities have not disclosed how much information was compromised or which categories of records were accessed.

The Service for Foreigners Affairs also opened an internal investigation into whether staff negligence delayed measures that could have limited the intrusion.

Slovakia reports Russian-linked attacks on strategic sectors

Slovak authorities confirmed in July that actors linked to Russia's Federal Security Service had targeted the country's critical infrastructure and companies in the energy, defense and automotive sectors.

The disclosure followed media inquiries rather than an initial public announcement by the government.

The European Union subsequently imposed sanctions on nine individuals in connection with the wider cyber campaign.

Attacks expose dependence on civilian government networks

The incidents differ in method, suspected motivation and impact. There is no evidence presented by authorities that the attacks in Poland, Latvia, Romania, Hungary, Croatia, Bosnia and Herzegovina and Slovakia form a single campaign.

Their targets nevertheless have something important in common. Medical records, land registries, vehicle databases, migration systems and treasury networks sit largely outside the traditional military security perimeter, but governments depend on them to perform basic state functions.

Romania provides one of the clearest examples. The e-Terra attack did not stop at stealing information. By wiping the production database and backups, the attacker temporarily disrupted the system used to register property transactions and establish ownership.

The Polish power plant intrusion demonstrated a different risk. Attackers reached operational equipment and shut down a turbine and water treatment system, although operators prevented the incident from interrupting electricity and heat supplies.

The Latvian and Polish data breaches illustrate the scale of information concentrated in individual platforms. Approximately 1.2 million people were affected by the Latvian road authority breach, while the MyDr incident in Poland involved records associated with nearly 19 million people.

These cases arrive as European Union member states implement the NIS2 Directive, which expands cybersecurity requirements across 18 critical sectors and introduces stricter obligations covering risk management, incident reporting and supply-chain security.

The challenge for governments in Central and Eastern Europe is increasingly not limited to protecting classified networks or military infrastructure. A compromised registry, health platform or industrial control connection can disrupt services that citizens, companies and public authorities depend on every day.


Questions about cyberattacks in Central and Eastern Europe

Which countries have reported major government cyberattacks in 2026?

Poland, Latvia, Romania, Hungary, Croatia, Bosnia and Herzegovina and Slovakia have reported significant incidents affecting government institutions, state-owned companies or critical infrastructure in the cases examined by AdriaDefense.

Are the cyberattacks connected?

Authorities have not presented evidence that the incidents form a single coordinated campaign. The cases involve different methods and apparent motivations, including ransomware, data theft and activity attributed to Russian state-linked actors.

What government systems have been targeted?

Affected systems include electronic medical records, vehicle and personal identification databases, land ownership records, migration systems, treasury infrastructure and energy facilities.

Why are civilian government systems significant cyber targets?

These networks support services required for routine government and economic activity. Disrupting them can affect property transactions, healthcare administration, migration procedures or energy operations without an attacker gaining access to a military network.