Cybersecurity incident at Kozminski University

08.06.2026

We would like to inform you that a cybersecurity incident involving ransomware has been identified within Kozminski University’s IT infrastructure.

Immediately after detecting the incident, security procedures were launched without delay. The IT team, together with external experts, is taking steps to fully determine the scope of the event, secure the systems, and mitigate its effects. The matter has been reported to CERT Polska, the Police, and the President of the Personal Data Protection Office.

At this stage of the analysis, not all circumstances of the incident have yet been confirmed. If we obtain any new information relevant to your security or to the university’s operations, we will share further updates.

Please exercise particular caution and follow the recommendations below:

  • change your password for university systems immediately;

you can do this on the following pages: https://my.kozminski.edu.pl/, https://haslo.kozminski.edu.pl/ or https://password.kozminski.edu.pl/;

  • if you use the same or a similar password for other services (e.g. private email, social media, online banking), change it there as well;
  • use multi-factor authentication wherever it is available;
  • be especially cautious with emails, text messages, links, and attachments from unknown senders;
  • do not install software from unverified sources;
  • report any unusual system behaviour or suspicious messages to the IT Department immediately.

At the same time, we kindly ask that any questions from the media or from individuals outside the university be directed to the Press Spokesperson. At this stage, it is particularly important that only verified information be communicated.

Paulina Łukaszuk – Press Spokesperson [email protected], tel. +48 609 500 462.

For matters related to personal data protection, please contact the Data Protection Officer:

Paweł Sidor, email: [email protected], tel. 22 519 21 33.

For technical matters, please contact the IT Department:

  • In person in room A-20, where the Central Customer Service Point (Technical Department) is also located,
  • By phone at +48 22 519 21 45,
  • By email at [email protected].

Thank you for your cooperation and responsible approach. Data security and the continuity of the university’s operations remain our highest priorities.

***

Q&A – Cybersecurity Incident at Kozminski University

1. What happened?

A cybersecurity incident involving ransomware-type malicious software was identified in part of Kozminski University’s IT infrastructure. The University has activated its security procedures and is conducting a detailed technical and legal analysis.

2. Has there been a personal data breach?

At this stage, it has been established that a personal data breach may have occurred. The exact scope of the incident is being determined, including the categories of data and the groups of individuals who may be affected.

3. Has my data been disclosed?

A detailed verification process is ongoing. Individuals whose data may have been affected by the breach will be informed in accordance with applicable regulations.

4. What data may have been affected by the breach?

The scope of the data is currently being verified. Once the relevant analyses have been completed, the University will provide the individuals concerned with information that is as precise as possible.

5. Has my PESEL number been leaked?

At this stage, we are not providing unverified information. If the analysis confirms that a given person’s PESEL number may have been affected by the breach, that person will be informed.

6. Should I restrict my PESEL number or ID card?

At this stage, we primarily recommend increased caution and monitoring any suspicious contacts. If a person receives individual information that their identification data may have been affected by the breach, it is worth considering additional protective measures, including restricting the PESEL number.

7. Have payment card details been leaked?

We currently have no information confirming a breach of payment card details. If such findings emerge, the individuals who may be affected will be informed.

8. Is my account in Kozminski University systems secure?

The University is taking steps to secure its systems and verify their integrity. We recommend changing your password for University systems and enabling multi-factor authentication wherever it is available. You can change your password on the following pages: https://my.kozminski.edu.pl/, https://haslo.kozminski.edu.pl/ lub https://password.kozminski.edu.pl/.

9. Do I need to change my password only in University systems?

No. If the same or a similar password was also used elsewhere, for example in private email, online banking, social media or other services, it should be changed there as well. Each system should have a unique password.

10. Can I continue using University systems?

Yes, provided that the given system is available and you have not received different instructions from the University or the IT Department. Please follow all current technical announcements.

11. Are classes, exams and student services continuing as normal?

The University is taking steps to limit the impact of the incident on its day-to-day operations. Any organisational changes will be communicated separately to the relevant groups.

12. Does the incident concern students, employees, alumni or candidates?

The University is currently determining which groups of individuals may be affected by the incident. If the analysis confirms a risk for a specific group, the individuals concerned will receive appropriate information.

13. What did the University do after detecting the incident?

Security procedures were activated, a technical analysis was launched, measures were taken to limit the impact of the incident, systems were secured, and the matter was reported to the relevant institutions.

14. What may be the consequences for the individuals whose data is affected?

Possible risks include attempts at impersonation, phishing, information fraud or unauthorised use of data. For this reason, we ask you to exercise particular caution with suspicious messages, links, attachments, text messages and phone calls.

 

15. What should I do now?

We recommend:

  • changing passwords for University systems; You can change your password on the following pages: https://my.kozminski.edu.pl/, https://haslo.kozminski.edu.pl/ or https://password.kozminski.edu.pl/.
  • changing passwords in other services if the same or a similar password was used there;
  • enabling multi-factor authentication;
  • exercising caution with suspicious messages, links and attachments, including carefully checking the sender’s details and verifying the content directly with the institution that allegedly sent the message;
  • monitoring activity on your accounts.

16. Will the University provide updates on further findings?

Yes. If new information relevant to data security or the functioning of the University becomes available, it will be communicated to the appropriate groups of recipients.

17. Where can I obtain more information?

For matters related to personal data protection, please contact the Data Protection Officer:

Paweł Sidor, email: [email protected], tel. 22 519 21 33.

For technical matters, please contact the IT Department:

  • In person in room A-20, where the Central Customer Service Point is also located (Technical Department);
  • By phone at22 519 21 45;
  • By email at [email protected].

See also