[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feo0b7ie5aasc":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":17,"affectedCount":17,"affectedCountStatus":18,"affectedCountLowerBound":19,"affectedCountUnit":20,"hasEnglishDescription":4,"severity":21,"dataClasses":22,"description":25,"seoTitle":15,"seoTitleEn":26,"seoDescription":15,"seoDescriptionEn":27,"logoUrl":28,"isVerified":4,"isSensitive":29,"isSpamList":29,"isMalware":29,"company":30},"68e3266eda11adda4882530d","certpoland-phish","Phished Data via CERT Poland Data Breach","phished-data-via-cert-poland","cert.pl","2023-02-25T00:00:00.000Z","2023-08-31T05:53:44.000Z","2026-07-29T12:19:53.122Z","Phishing","",[],67943,"known",null,"unknown","Medium",[23,24],"Email addresses","Passwords","\u003Cp>Phished Data via CERT Poland data breach is the email and password leak collected through a phishing campaign in February 2023, affecting approximately 67,943 accounts. This record should not be interpreted as a breach of the CERT Poland site; the naming comes from identifying data obtained through phishing in the context of a security notification. The main risk for the user is that the email address and password are found together and these credentials can be tried on other accounts.\u003C\u002Fp> \u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2> \u003Cp>The data fields verified in the record are email addresses and passwords. Full name, phone number, address, payment information, ID document, or additional profile fields are not included in the description because they are not verified. Since there is a password field, the record is high risk. If the user has reused the same password on email, banking, work, social media, shopping, or cloud services, attackers can use this information in automated login attempts. The email account should also be prioritized for protection because it contains reset links for other accounts.\u003C\u002Fp> \u003Ch2>Phishing and Purchase Order Context\u003C\u002Fh2> \u003Cp>The context of phishing indicates that the user may have entered the password through a fake form or misleading message. Therefore, simply changing the password may not be enough; the user should also consider which message or link led to the interaction. Similar emails may come again, and the same visual design or institution name may be used. Instead of clicking on a link in unexpected purchase confirmations, invoices, deliveries, document sharing, or account verification messages, users should go directly to the official address of the relevant service.\u003C\u002Fp> \u003Ch2>Password and Account Takeover Risk\u003C\u002Fh2> \u003Cp>The first step for affected users is to switch to unique new passwords on all important accounts used with this email address. Using a password manager makes it easier to detect repeated passwords and generate strong passwords for each account. Two-factor authentication should be enabled on every service where possible, unfamiliar sessions should be closed, and account recovery information should be updated. Forwarding rules, automatic filters, and third-party app permissions on the email account should also be checked.\u003C\u002Fp> \u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2> \u003Cp>Since this record contains a password, users should also check the security of their devices. The phishing page may have only collected the password; however, some campaigns may also direct to downloading malicious files or fake applications. If a suspicious attached file has been opened, a security scan should be performed, the operating system and browser should be updated, and suspicious extensions should be removed. Ensuring that the device and browser environment are secure before creating a new password reduces the risk.\u003C\u002Fp> \u003Ch2>Security Lessons for Institutions\u003C\u002Fh2> \u003Cp>The Phished Data via CERT Poland record for organizations is a direct warning that employees may have entered information into phishing forms. If emails belonging to the corporate domain are affected, identity provider logs, failed login attempts, new device registrations, and unusual geographic access should be examined. For critical users, password reset, session termination, multi-factor authentication, and phishing awareness training should be implemented together. Domain names and links of suspicious campaigns should be blocked in email security systems.\u003C\u002Fp> \u003Ch2>Necessary Precautions\u003C\u002Fh2> \u003Cp>Phished Data via CERT Poland data leak poses a direct account security risk due to email and password fields. When users see this record, they should separate all accounts using the same password, strengthen their email account, and be more cautious against similar phishing messages. The most accurate approach is to treat the incident not only as a record of a past password, but as a comprehensive warning in terms of user behavior, account security, and phishing defense.\u003C\u002Fp> \u003Cp>The critical point in the Phished Data via CERT Poland record is that the data was collected through phishing. If a user entered their password into a fake form, the same attack pattern could be tried again. Therefore, users should not only change their current password but also reassess which messages they should not trust. Emails themed around purchase confirmation, invoices, shipping, document sharing, and security verification should be checked particularly carefully. Going directly to the official website is safer than clicking on a link.\u003C\u002Fp> \u003Cp>This record should be treated as a real authentication event for institutions. If there is a match between the employee's address and password, central sessions should be refreshed, suspicious login attempts should be reviewed, and password reuse should be prevented. The possibility that the user has used the same password on other systems should not be overlooked. For a secure outcome, password renewal, multi-factor authentication, session termination, phishing training, and email security rules should be applied together.\u003C\u002Fp>","Phished Data via CERT Poland Data Breach (67.9 Thousand Reported Records)","Phished Data via CERT Poland Data Breach. 67.9 Thousand reported records were reported. Reported data: Email addresses, Passwords. Review the scope, risks…","\u002Fuploads\u002Flogo\u002Fcert_polska_official.ico",false,{"name":31,"sector":32,"country":33,"website":10,"websiteArchiveUrl":15,"websiteStatus":15,"websiteCheckedAt":19},"Phished Data via CERT Poland","Other","Poland"]