A nuclear research cyberattack targeting Poland’s National Centre for Nuclear Research (NCBJ) was detected and blocked in early March 2026, with Polish authorities announcing on March 13 that security systems had intercepted the intrusion before any damage could occur. The NCBJ is Poland’s main government nuclear research institute, covering nuclear physics, reactor technology, particle physics, and radiation applications — making it a high-value target for any state-level adversary.
TL;DR: Poland successfully blocked a cyberattack on the NCBJ in early March 2026. No research, production, or operational activities were disrupted. Polish authorities identified “many indications” pointing to Iran as the source, but explicitly cautioned the evidence could be deliberate misdirection.
What happened in the Poland nuclear research cyberattack?
Security systems at the NCBJ detected and neutralised the intrusion before it could cause any operational damage. No production, research, or operational activities were disrupted, and Poland’s only nuclear reactor — the MARIA reactor — continued operating safely at full power throughout the incident. The attack was blocked entirely at the IT infrastructure level.
The MARIA reactor is worth understanding in context. It’s not a power-generation facility — it’s used for scientific experiments, neutron research, and medical isotope production. That last function matters enormously: a successful disruption could have had downstream consequences for medical supply chains, not just research timelines. The attackers, whoever they were, chose their target carefully.
NCBJ coordinated its response with NASK-PIB, the Ministry of Digital Affairs, Deputy Prime Minister Krzysztof Gawkowski, and the Ministry of Energy. Internal security teams were placed on high alert following the detection.
Is Iran behind the nuclear research cyberattack on Poland?
Polish investigators found “many indications” and “signs” suggesting Iran may be responsible for the attack, but they explicitly cautioned that these indicators could be deliberate misdirection designed to conceal the attackers’ true origin. No specific threat group has been publicly confirmed by NCBJ. Attribution in state-level cyberattacks is notoriously difficult, and the investigators’ own caveat is the most honest thing in this story.
The caution is well-founded. False flag operations — where attackers plant indicators pointing to a rival nation — are a standard tool in sophisticated cyber espionage. The fact that Polish authorities are publicly flagging this possibility suggests they’re taking the misdirection hypothesis seriously, not just covering their bases for press releases.
How does this fit Poland’s broader cyberattack problem?
Poland has been under sustained digital pressure for months. In January 2026, cybersecurity firm ESET linked a late-2025 attack on Poland’s energy system to Sandworm, a Russia-linked advanced persistent threat group. Separately, a report published in late February 2026 by the ICCT placed Poland high on Russian cyber-actors’ target list, citing 31 confirmed incidents between mid-2025 and early 2026. That’s a significant tempo of attacks against a single NATO member state.
The NCBJ incident sits within this pattern, but with a twist: the suspected origin is Iran, not Russia. Whether that reflects a genuine Iranian operation, a Russian false flag, or an entirely different actor remains unresolved. What’s clear is that Poland’s critical infrastructure is being probed repeatedly and from multiple directions — and that the NCBJ’s security systems performed exactly as they should have.
Comparing this to the January 2026 energy grid attack is instructive. That incident, attributed by ESET to Sandworm, targeted electricity infrastructure — a different sector but the same underlying logic: disrupt systems that a modern state depends on. Nuclear research facilities add a psychological dimension that power grids don’t. Even a failed attack on a nuclear site generates headlines and public anxiety, which may itself be part of the objective.
Should we be worried about nuclear facility cybersecurity?
The NCBJ attack was blocked, which is the outcome security teams train for. But the fact that a nuclear research facility was targeted at all — during a period of heightened geopolitical tension in Europe — is a signal worth taking seriously. Critical infrastructure attacks don’t need to succeed to achieve their goals; the attempt alone forces resources into defensive postures and erodes public confidence.
The MARIA reactor’s dual role in medical isotope production makes the NCBJ a more complex target than a standard research facility. Any disruption to isotope supply chains would have real-world consequences for patients, not just scientists. Defenders at facilities like this aren’t just protecting data — they’re protecting supply chains that hospitals depend on.
Who is suspected of attacking Poland’s nuclear research centre?
Polish authorities identified “many indications” pointing to Iran as the source of the March 2026 attack on the NCBJ, according to reporting by the Times of Israel and Security Affairs. However, investigators explicitly stated these indicators could be deliberate misdirection. No specific threat group or individual has been formally named. The investigation remains ongoing.
Was the MARIA reactor affected by the cyberattack?
No. Poland’s MARIA reactor — the country’s only nuclear reactor, used for scientific experiments, neutron research, and medical isotope production — continued operating safely at full power throughout the incident. The attack targeted IT infrastructure and was blocked before it could affect any operational or research systems.
The NCBJ attack ended without damage, but it shouldn’t end without consequence. Poland and its NATO partners need to treat the sustained targeting of critical infrastructure — energy grids, nuclear research facilities, and whatever comes next — as a coordinated campaign, not a series of isolated incidents. Blocking one attack is a success. Assuming the next one will be equally straightforward is a mistake.
Edited by the All Things Geek team.
Source: TechRadar

