Tuesday 13 May 2025, Safety Guide
Password leak from 5 Polish portals

Lost24
Five Polish organizations fell victim to an attack by a group of hacktivists who published data stolen from their websites. The leak included password hashes, email addresses, and personal data. In most cases, a SQL Injection vulnerability was used. The identified victims are:
Stawki Housing Cooperative (smstawki.pl) – leak of 320 records containing residents' data; an information campaign and password change are planned.
Końskie Towarzystwo Budownictwa Społecznego (ktbs-kolo.pl) – the data was authentic, but did not contain personal data or allow logging in.
AGH University of Science and Technology (AGH) (home.agh.edu.pl) – leak of only 47 emails; the data came from an application created by an employee; the inciden