Cyberattack Targeting the National Centre for Nuclear Research (NCBJ)

Critical Infrastructure Nuclear Sector Cyberattack
Overview
Polish authorities detected and blocked a cyberattack targeting the IT infrastructure of the National Centre for Nuclear Research (NCBJ). The intrusion attempt aimed to access internal systems, but security monitoring identified suspicious activity early and defenders contained the threat before operational systems were affected.
Initial investigation suggested possible links to infrastructure associated with actors in Iran. Attribution remains unconfirmed and investigators noted that false-flag techniques are possible.
Technical Specifications
| Field | Details |
|---|---|
| Incident Type | Targeted cyberattack / unauthorized access attempt |
| Primary Target | National Centre for Nuclear Research (NCBJ), Poland |
| Target Environment | IT infrastructure and internal networks |
| Detection Method | Security monitoring, unauthorized access alerts, abnormal network activity |
| Operational Impact | No disruption to reactor or nuclear research operations |
| Attribution Status | Under investigation; possible Iran-linked infrastructure noted |
Affected Products
- NCBJ internal IT systems and network segments.
- No reported compromise of industrial control systems (ICS) or reactor control systems.
- MARIA research reactor operations remained normal.
Technical Details
- Attack activity focused on IT infrastructure and internal networks of the research center.
- Security systems detected unauthorized access attempts and anomalous network behavior.
- No compromise of ICS or reactor control systems was reported.
- Indicators of compromise suggested potential links to infrastructure previously associated with Iran-linked actors, though attribution is still pending.
- Incident response teams isolated affected systems and started forensic analysis.
Attack Scenario
- Threat actors attempted to gain access to the research center's IT environment.
- The intrusion likely involved reconnaissance and/or credential-based access attempts.
- Monitoring controls detected suspicious behavior and unauthorized access attempts.
- The organization activated incident response procedures.
- Security teams isolated systems and blocked the intrusion before lateral movement or access to sensitive assets.
Impact Assessment
No disruption to nuclear research operations was reported.
No evidence indicated compromise of reactor systems or safety-related controls.
No reported data exfiltration was disclosed, and the incident triggered a national cybersecurity investigation with elevated monitoring of critical infrastructure.
Mitigation Strategies
- Maintain layered network monitoring and intrusion detection systems.
- Execute rapid incident response playbooks, including containment and system isolation.
- Coordinate with national cybersecurity authorities for investigation and threat intelligence sharing.
- Apply continuous monitoring of critical infrastructure networks.
- Strengthen authentication controls and enforce segmentation between IT and operational technology (OT) environments.
Resources
Open-Source Reporting
- Hackers targeted Poland's National Centre for Nuclear Research
- Poland says foiled cyberattack on nuclear centre may have come from Iran | Reuters
- Poland's nuclear research centre targeted by cyberattack
- Nuclear Facility Cyberattack Investigated as Possible Iranian Exploit | Security Magazine
- Poland says Iran may be behind foiled cyberattack on nuclear center | Iran International
Last Updated: March 15, 2026