<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>phishing - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/phishing/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Mon, 07 Sep 2026 20:31:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 20:30:11 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Act on Patients Rights]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI cybersecurity]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI-enabled attacks]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anonymisation]]></category>
		<category><![CDATA[anonymization]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[cloud healthcare]]></category>
		<category><![CDATA[controller liability]]></category>
		<category><![CDATA[Cyber Five]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[cyber resilience healthcare]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach response]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data minimisation]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data processing agreement]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection impact assessment]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[digital healthcare]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[e-health]]></category>
		<category><![CDATA[eHealth platforms]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR security]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Article 28]]></category>
		<category><![CDATA[GDPR Article 32]]></category>
		<category><![CDATA[GDPR Article 33]]></category>
		<category><![CDATA[GDPR Article 34]]></category>
		<category><![CDATA[GDPR Article 35]]></category>
		<category><![CDATA[GDPR Article 82]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR compliance healthcare]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare AI]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[healthcare contracts]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[healthcare data security]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[healthcare software]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT supplier contracts]]></category>
		<category><![CDATA[joint and several liability]]></category>
		<category><![CDATA[liability insurance]]></category>
		<category><![CDATA[medical data protection]]></category>
		<category><![CDATA[medical records]]></category>
		<category><![CDATA[medical technology]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[MyDr data breach]]></category>
		<category><![CDATA[National Cybersecurity System]]></category>
		<category><![CDATA[network segmentation]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[patient privacy]]></category>
		<category><![CDATA[patients rights]]></category>
		<category><![CDATA[Personal data breach]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attacks]]></category>
		<category><![CDATA[Poland cybersecurity]]></category>
		<category><![CDATA[Polish GDPR]]></category>
		<category><![CDATA[Polish healthcare law]]></category>
		<category><![CDATA[privacy by design]]></category>
		<category><![CDATA[processor liability]]></category>
		<category><![CDATA[pseudonymisation]]></category>
		<category><![CDATA[pseudonymization]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[special category data]]></category>
		<category><![CDATA[sub-processors]]></category>
		<category><![CDATA[subprocessor management]]></category>
		<category><![CDATA[supplier risk management]]></category>
		<category><![CDATA[technology contracts]]></category>
		<category><![CDATA[telemedicine]]></category>
		<category><![CDATA[third-party liability]]></category>
		<category><![CDATA[UODO]]></category>
		<category><![CDATA[vendor risk]]></category>
		<category><![CDATA[voice deepfake]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8909</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 What happened On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<h2 class="wp-block-heading"><strong>What happened</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:42% auto"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4"></video></figure><div class="wp-block-media-text__content">
<p>On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.</p>
</div></div>



<p>The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.</p>



<span id="more-8909"></span>



<p>To date, the company has not publicly confirmed the full scope and nature of the compromised data, referring instead to a pending forensic analysis. The investigation is being conducted by the Central Bureau for Combating Cybercrime under the supervision of the Warsaw Regional Prosecutor&#8217;s Office, and the President of the Personal Data Protection Office (UODO) has opened an inspection covering the technical and organisational measures applied and the underlying risk analysis. Since 29 August, the dataset from the incident has been available on the government portal bezpiecznedane.gov.pl, where anyone can check whether their data was affected.</p>



<p>The scale of the incident prompted the Ministry of Digital Affairs to announce, within three weeks, a legislative package branded the &#8220;Cyber Five&#8221;. Its key elements include certification of entities processing medical data within the existing national cybersecurity certification framework; a mandatory risk assessment before processing begins and at least every two years thereafter; new obligations for entities serving more than 100 controllers or processing data of more than 100,000 individuals (including rapid transfer of affected persons&#8217; data to CSIRT NASK and a duty to inform client facilities about the level of their own security); and notifications of medical events via the mObywatel and mojeIKP applications. The amendments are to cover the Act on Patients&#8217; Rights and the legislation governing the National Cybersecurity System.</p>



<h2 class="wp-block-heading"><strong>Why roles in the processing chain decide everything</strong></h2>



<p>From a legal standpoint, the critical point is that, in relation to medical records, MyDr acts as a processor, while each facility – from a large clinic network to a single-doctor practice – remains the controller. The consequences of this structure became fully apparent after the incident:</p>



<ul class="wp-block-list">
<li><strong>The obligation to notify UODO (Article 33 GDPR) and to communicate the breach to patients (Article 34 GDPR)</strong> rests with the controller, i.e. the facility. The processor is merely required to inform the controller &#8220;without undue delay&#8221; (Article 33(2) GDPR). In practice, thousands of healthcare providers had to assess risk and communicate with patients on the basis of fragmentary information from the supplier.</li>



<li><strong>Liability for damages (Article 82 GDPR)</strong> is joint and several: a patient may sue the facility, the supplier, or both. The processor is liable where it has failed to comply with obligations specifically imposed on processors by the GDPR or acted contrary to the controller&#8217;s instructions – but the facility is liable for having entrusted data to an entity that did not provide sufficient guarantees (Article 28(1) GDPR).</li>



<li><strong>Sector-specific requirements under the Act on Patients&#8217; Rights</strong> (Article 24(4)) impose on any entity entrusted with the processing of medical records a duty of confidentiality and data security – this is precisely the provision now slated for extension to include certification and minimum technological standards.</li>
</ul>



<p>Deputy Minister of Digital Affairs Dariusz Standerski stated openly that in this case, liability under the contract remained entirely with the controllers, i.e. small medical practices. This is the most important lesson of the incident: a data processing agreement is not a formality but the document that, on the day of a breach, determines who pays.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How a healthcare service provider can protect itself</strong></h2>



<p><strong>1. The data processing agreement and the main contract as risk-allocation tools.</strong> Standard DPA templates offered by software vendors focus on satisfying the minimum requirements of Article 28(3) GDPR. A healthcare provider should negotiate further: a precise deadline and format for incident notification (e.g. 24 hours, with a defined scope of information enabling a risk assessment); audit and penetration-testing rights; an obligation to maintain specified certifications (ISO 27001 and, in future, certification under the National Cybersecurity System Act); a duty to cooperate in communications with patients and the supervisory authority; liability and recourse clauses not capped at the annual fee; and a requirement that the vendor hold cyber insurance with a defined sum insured, with the facility named as a co-insured or beneficiary.</p>



<p><strong>2. Cyber and liability insurance.</strong> Standard professional liability policies for healthcare providers typically do not cover the cost of notifying patients, crisis management, administrative fines or claims arising from data breaches. A dedicated cyber policy covers these elements, but its exclusions must be read carefully: insurers increasingly condition cover on the implementation of MFA, system patching and backups, and an incident at an external supplier (a so-called <em>third-party breach</em>) is often covered only under an express extension. It is also worth verifying whether the software vendor&#8217;s own policy actually exists and what its limit is – given the number of facilities relying on a single system, such amounts may prove illusory.</p>



<p><strong>3. A map of relationships between entities.</strong> In a real-world e-health ecosystem, patient data flows between the facility, the EMR vendor, the hosting or cloud provider, the e-prescription and e-referral operator, laboratories, IT subcontractors and billing companies. Each link is a distinct legal relationship: processing on behalf of the controller, sub-processing (Article 28(2) and (4) GDPR) or joint controllership (Article 26 GDPR). A facility should maintain an up-to-date register of these entities, know where the data is physically located and control the chain of sub-processors – a &#8220;general&#8221; consent to sub-processors without a list and without a right to object is, in practice, an abdication of control.</p>



<p><strong>4. Anonymisation, pseudonymisation and data minimisation.</strong> Data that is not in the system cannot leak. Healthcare providers and vendors should separate identifiers (PESEL numbers, contact details) from clinical data, apply pseudonymisation (Article 4(5) and Article 32(1)(a) GDPR) in test, analytical and research environments, and store statistical data exclusively in anonymised form. It should be remembered that anonymisation is an irreversible process and only such a process removes data from the scope of the GDPR; pseudonymisation remains processing of personal data, but it significantly limits the consequences of a breach and is a valuable argument both in proceedings before UODO and in litigation over damages.</p>



<p><strong>5. Internal obligations and incident readiness.</strong> A breach response procedure should be tested, not merely written down: who decides on notifying UODO within 72 hours, who communicates with patients, who with the media, who secures the evidence. Regular risk analysis and a data protection impact assessment (DPIA) for EMR systems – which, given their scale and the categories of data involved, almost always meet the criteria of Article 35 GDPR – is an obligation already today, and once the &#8220;Cyber Five&#8221; enters into force it will additionally become a sector-specific requirement with a prescribed frequency.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>AI-enabled attacks</strong></h2>



<p>The healthcare sector is particularly exposed to a new generation of AI-supported attacks. Large language models enable the mass generation of credible phishing messages in flawless Polish, personalised on the basis of data from previous breaches – a PESEL number, a surname and information about a prescription are enough to construct a convincing message &#8220;from your clinic&#8221; or &#8220;from the National Health Fund&#8221;. AI tools also automate the discovery of vulnerabilities in systems and the generation of malicious code, shortening the window between disclosure of a vulnerability and its exploitation. There is a growing number of cases involving voice deepfakes used to impersonate medical staff or IT administrators in order to obtain access credentials.</p>



<p>For vendors and facilities, this means that traditional &#8220;don&#8217;t click suspicious links&#8221; training is no longer sufficient. Technical mechanisms are required (phishing-resistant MFA, network segmentation, AI-assisted anomaly monitoring on the defensive side), together with identity verification procedures for every request for data access or a change of permissions. Regulatory risk should also be kept in mind: AI systems deployed in healthcare facilities – including tools supporting diagnostics or triage – fall under the AI Act, and their integration with EMR systems constitutes yet another link in the processing chain that must be reflected in contracts and in the risk analysis.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How we support institutional clients</strong></h2>



<p>KG Legal advises healthcare providers, medical networks, telemedicine platform and e-health software vendors, and investors in this sector on managing liability for data. Our support includes auditing existing data processing agreements and IT supplier contracts for risk allocation; negotiating liability, recourse and insurance clauses; mapping the chain of processors and vetting subcontractors; preparing and testing breach response procedures; handling notifications to UODO and communications with patients; and representation in inspection proceedings and in damages litigation. For medical technology vendors, we prepare documentation and contract templates meeting the requirements of the GDPR, the Act on Patients&#8217; Rights, NIS2 and – once enacted – the &#8220;Cyber Five&#8221; provisions, and we assess the compliance of AI-based solutions with the AI Act and the MDR. Our aim is that, on the day an incident occurs, the client knows exactly who is responsible for what and has evidence of having exercised due diligence.</p>



<p><em>Facts as at 2 September 2026, based on statements by MyDr, the Ministry of Digital Affairs and UODO, and press reports. This article is for information purposes only and does not constitute legal advice.</em></p>
<p>#MyDr #DataBreach #HealthcareCybersecurity #HealthcareData #DataProtection #GDPR #Cybersecurity #HealthTech #eHealth #DigitalHealth #MedicalRecords #EMR #PatientData #PatientPrivacy #UODO #Poland #CyberRisk #CyberInsurance #IncidentResponse #DataPrivacy #NIS2 #CyberFive #ISO27001 #AIAct #AIinHealthcare #AICybersecurity #MedTech #Telemedicine #CyberResilience #DataSecurity</p>
<p> </p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4" length="492961" type="video/mp4" />

			</item>
		<item>
		<title>Acts of Abuse in Electronic Communications, procedures and cooperation with authorities in EU and Poland</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/acts-of-abuse-in-electronic-communications-procedures-and-cooperation-with-authorities-in-eu-and-poland/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/acts-of-abuse-in-electronic-communications-procedures-and-cooperation-with-authorities-in-eu-and-poland/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 18 Nov 2025 12:06:08 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Acts of Abuse]]></category>
		<category><![CDATA[CSIRT NASK]]></category>
		<category><![CDATA[Electronic Communications]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[President of the Office of Electronic Communications]]></category>
		<category><![CDATA[Smishing Distribution]]></category>
		<category><![CDATA[The Polish Act on Combating Abuse in Electronic Communications]]></category>
		<category><![CDATA[UKE]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8488</guid>

					<description><![CDATA[<p>Publication date: November 18, 2025 With technological advancements, scams involving phishing, smishing, spoofing, and CLI spoofing are gaining popularity. While they are not a new phenomenon, AI technologies certainly allow for increasingly faster and more effective image and voice impersonation, making impersonation easier. Furthermore, the latest tools help perpetrators tailor their manipulation techniques to specific [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/acts-of-abuse-in-electronic-communications-procedures-and-cooperation-with-authorities-in-eu-and-poland/">Acts of Abuse in Electronic Communications, procedures and cooperation with authorities in EU and Poland</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: November 18, 2025</mark></mark></strong></p>



<p>With technological advancements, scams involving phishing, smishing, spoofing, and CLI spoofing are gaining popularity. While they are not a new phenomenon, AI technologies certainly allow for increasingly faster and more effective image and voice impersonation, making impersonation easier. Furthermore, the latest tools help perpetrators tailor their manipulation techniques to specific individuals. Such activities serve a variety of purposes, from extorting personal data or stealing logins and passwords to persuading or intimidating victims into unfavorable financial transactions. <strong>The Polish Act on Combating Abuse in Electronic Communications </strong>aims to create mechanisms to limit these harmful phenomena. It aims to increase user protection against harmful activities carried out via communication technologies, such as text message fraud, data theft, and unfavorable financial transactions.</p>



<span id="more-8488"></span>



<p><strong><u>Polish Act on Combating Abuse in Electronic Communications</u></strong></p>



<p>The Polish Act on Combating Abuse in Electronic Communications entered into force on September 25, 2023. Its material scope covers the rights and obligations of telecommunications companies, email providers, and public entities with respect to preventing and combating abuse in electronic communications (Article 1, point 1). CSIRT NASK is to play a special role in implementing the statutory tasks (Article 4). The concept of &#8220;abuse in electronic communications&#8221; has been defined as the provision or use of a telecommunications service or telecommunications equipment that is contrary to their intended purpose or legal provisions (Article 2, point 8), where the purpose or effect is to cause harm to a telecommunications undertaking or end user, or to obtain undue benefits for the entity committing the abuse of electronic communications, another natural person, legal person or organizational unit without legal personality. The Act prohibits, in particular, generating artificial traffic (sending or receiving messages or voice calls, the sole purpose of which is to be registered at the point of connection of telecommunications networks or by billing systems), smishing (a type of phishing carried out using SMS messages in which the sender impersonates another entity), CLI spoofing (impersonation by the caller using someone else&#8217;s address information in a voice call) and unauthorized change of address information (unlawful modification of address information in a way that prevents or makes it difficult to determine who the sender of the message is). Activities other than those mentioned may also constitute abuse of electronic communications.</p>



<p><strong>Phishing</strong></p>



<p>Phishing occurs when websites attempt to extort data. This is the most serious threat in Poland. The Act on Combating Abuse in Electronic Communications provides for the warning list, which has been in effect since March 2020 (Articles 20 and 39, paragraph 3). The list allows internet providers who enter into an agreement with the Ministry of Digital Affairs, NASK, to block traffic to phishing websites at the DNS server level. The warning list is public and covers internet domains used for data theft and the detrimental disposal of internet users&#8217; property. It also includes internet domains whose primary purpose is to mislead internet users and lead to the extortion of their data or the detrimental disposal of their property (Article 20, paragraph 3). Anyone can submit an internet domain, with the option of providing justification (Article 20, paragraph 4), but the NASK CSIRT can also, on its own initiative, add a domain to the warning list (Article 20, paragraph 5). A telecommunications company may prevent internet users from accessing websites using domain names included in the warning list by removing them from the telecommunications company&#8217;s IT systems used to convert domain names to IP addresses (Art. 20, Section 8). In such a case, the telecommunications company will redirect connections referring to domain names included in the warning list to a website maintained by CSIRT NASK containing information addressed to internet users, including, in particular, information about the location of the warning list, the inclusion of the searched domain name in the warning list, and possible attempts at data fraud or unfavorable disposal of property (Art. 20, Section 9). Pursuant to Art. 21, <strong>an objection to the inclusion of an internet domain in the warning list may be filed with the President of the Office of Electronic Communications.</strong></p>



<p>The objection should include:</p>



<p>• indication of the Internet domain to which the objection relates;</p>



<p>• a justification explaining why the inclusion of the Internet domain in the warning list is unjustified;</p>



<p>• data identifying the entity holding the legal title to the Internet domain:</p>



<p>• in the case of natural persons – name and surname, address of residence;</p>



<p>• in the case of legal persons and organizational units without legal personality – name of the entity, registered office address, number from the relevant register;</p>



<p>• name and surname of the person authorized to represent the entity holding the legal title to the Internet domain, together with authorization.</p>



<p>Article 22 states that the President of the Office of Electronic Communications (UKE) (or another authorized body) shall consider the objection within 14 days of its receipt and shall immediately inform the objecting entity of the outcome of its consideration. If the domain name is not used for data fraud or for the detrimental disposal of internet users&#8217; property, the objection is upheld (Article 22, paragraph 2, point 1). Within three days of upholding the objection, the NASK CSIRT removes the domain from the warning list (Article 22, paragraph 3). Otherwise, the President of the UKE does not uphold the objection (Article 22, paragraph 2, point 2), but such a decision can be appealed to an administrative court.</p>



<p>A domain may be removed from the list once the grounds for its inclusion cease to exist. In such a case, operators should immediately cease blocking it. Each operator may independently decide to unblock a domain early. The appeal can be justified by stating that the decision was based on an incorrect classification and that the website did not contain phishing content or content infringing on personal rights or copyrights, that any infection or content hijacking was immediately removed, or that the measure taken proved disproportionate to the actual threat.</p>



<p><strong>Smishing Distribution</strong></p>



<p>Smishing is the distribution of links to phishing websites via text messages (Article 3, point 2). Pursuant to the Act, CSIRT NASK monitors smishing and creates message templates that possess characteristics that allow them to be recognized as smishing (Article 4). This activity is based on reports of suspicious messages from recipients and information from telecommunications companies and other entities. Blocking this phenomenon is divided into two aspects. First, CSIRT NASK maintains a list of malicious message templates. Operators will be required to block an incoming message if it matches any template on the list. Each template must be made public within 14 to 21 days of its appearance on the list. Second, protection of SMS sender surnames used by public entities will be introduced. This process consists of two elements:</p>



<p>• creating a list of restricted SMS overrides and their malicious variants;</p>



<p>• list of SMS service integrators providing services to public entities, maintained by the Office of Electronic Communications.</p>



<p>Telecommunications companies may also block SMS messages other than those that conform to the template developed by CSIRT NASK, as well as MMS messages, using a system enabling automatic identification. Telecommunications companies may process and mutually share electronic messages to identify, prevent, and combat smishing (SMS and MMS) (Art. 26). Additionally, public entities may protect themselves against unauthorized use of their overrides by outsourcing the messaging service exclusively to a specific SMS integrator. Telecommunications companies are obligated to block SMS messages that:</p>



<p>• they contain an overlay reserved for a public entity and were not sent by an integrator serving a given public entity;</p>



<p>• contain a misleading variant of the public entity&#8217;s override, included in the CSIRT NASK list.</p>



<p>The SMS sender whose message has been blocked in this way has the right to file an objection to the President of the Office of Electronic Communications (Article 7). The objection should include:</p>



<p>• full text of the SMS;</p>



<p>• justification explaining why the content of the SMS does not constitute smishing ;</p>



<p>• indication of the number used to send the SMS;</p>



<p>• data identifying the sender:</p>



<p>Pursuant to Article 8, there is a 14-day period from the date of receipt of the objection to consider it, and then the SMS sender is informed of the outcome of the objection. If the SMS containing content consistent with the message template does not constitute smishing, the President of the UKE will uphold the objection. Otherwise, the objection will not be upheld. A complaint may be filed with an administrative court. A telecommunications undertaking engaging in smishing is subject to a fine (Article 37 paragraph 1 item 2). If the act also constitutes a criminal offence, only the provisions on criminal liability apply to a telecommunications undertaking that is a natural person (Article 27 paragraph 2). Furthermore, pursuant to Article 30, whoever, in order to gain financial or personal benefit or to cause harm to another person, sends an SMS, MMS or a message via other interpersonal communication services in which he or she impersonates another entity in order to persuade the recipient of the message to provide personal data, to dispose of property to an unfavorable extent, to open a website, to initiate a voice call, to install software, to provide computer passwords, access codes or other data enabling unauthorized access to information stored in an IT system, ICT system or ICT network &#8211; smishing &#8211; shall be subject to a penalty of imprisonment from 3 months to 5 years. In cases of lesser gravity, the perpetrator shall be subject to a fine, restriction of liberty or imprisonment for up to one year.</p>



<p><strong>Spoofing</strong></p>



<p>Spoofing is a form of fraud in which an attacker impersonates another person, company, or device to gain access to confidential information, money, or spread malware. This is most often done via email or phone calls. Spoofing can be used for phishing. Email providers serving at least 500,000 users or public entities are required to implement mechanisms designed to prevent a domain from being used to impersonate its owner or to alter messages sent from it:</p>



<p>SPF;</p>



<p>DMARC;</p>



<p>DKIM.</p>



<p>The Act imposes an obligation on public entities to use only email services that incorporate such mechanisms. Email providers that fail to meet these obligations may be subject to a fine if the scope or nature of the violation warrants it (Article 27, Section 4). Regardless of the fine, the President of the Office of Electronic Communications (UKE) may, by decision, impose on the manager of a telecommunications undertaking, in particular a person holding a managerial position or a member of the management body of a telecommunications undertaking or an association of such undertakings, a fine of up to 300% of their monthly remuneration, calculated according to the rules applicable to determining the monetary equivalent for vacation leave (Article 27, Section 6). Pursuant to Articles 40 and 41, <strong>email providers providing services to public entities that do not offer multi-factor authentication should have submitted an offer that would provide this functionality. </strong>The decision of the President of the Office of Electronic Communications (UKE) imposing a fine may be appealed to the District Court in Warsaw – the Court of Competition and Consumer Protection (Article 27, paragraph 9). Fines are subject to enforcement under the provisions on administrative enforcement proceedings for the enforcement of pecuniary obligations (Article 27, paragraph 10).</p>



<p><strong>CLI Spoofing</strong></p>



<p>This type of spoofing involves modifying the displayed number field of an incoming call. Unlike email security, there are no fully proven mechanisms in this case. Telecommunications companies are required to conceal number identification or block voice calls intended to impersonate another person or institution. Such numbers, which only serve as a receiving device and are easily linked to an institution, should be reported to the President of the Office of Electronic Communications (UKE), who has created a dedicated list for them. Telecommunications operators are obligated to block outgoing calls from numbers on this list (Article 16). The second obligation imposed on operators is to block or conceal the forged identifier if CLI spoofing is detected (Article 19). An operator that properly executes an agreement concluded with the President of the UKE specifying detailed organizational and technical measures to combat CLI spoofing (Article 19 paragraph 2) shall not be liable for non-performance or improper performance of a telecommunications service resulting from the organizational and technical measures applied (Article 19 paragraph 4). These rules apply to providers of publicly available telecommunications services providing services to at least 50,000 subscribers who are also operators (Article 19 paragraph 2). For other entrepreneurs, the President of the UKE may issue recommendations specifying detailed organizational and technical measures (Article 19 paragraph 6). If the obligations are properly fulfilled, such an entrepreneur shall not be liable for non-performance or improper performance of a telecommunications service resulting from the introduction of these measures. However, an entrepreneur who engages in CLI spoofing is subject to a fine (Article 27 paragraph 1 item 3). Of course, if the elements of a crime are met, only the provisions on criminal liability apply (Article 27 paragraph 2). According to Article 31, whoever, for the purpose of gaining material or personal benefit or causing harm to another person, when initiating a voice call, uses, without being authorized to do so, address information indicating another natural person, legal person, or organizational unit without legal personality, in order to impersonate another entity in order to persuade the recipient of the call to provide personal data, unfavorable disposal of property, or install software, provide computer passwords, access codes, or other data enabling unauthorized access to information stored in an IT system, ICT system, or ICT network &#8211; shall be subject to a penalty of imprisonment from 3 months to 5 years. In less serious cases, the perpetrator shall be subject to a fine, restriction of liberty, or imprisonment for up to one year. Pursuant to Art. 17, from 26 March 2024, the President of the Office of Electronic Communications shall maintain a public list of numbers used exclusively for receiving voice calls.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/acts-of-abuse-in-electronic-communications-procedures-and-cooperation-with-authorities-in-eu-and-poland/">Acts of Abuse in Electronic Communications, procedures and cooperation with authorities in EU and Poland</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/acts-of-abuse-in-electronic-communications-procedures-and-cooperation-with-authorities-in-eu-and-poland/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Spoofing and phishing in Polish law &#8211; current regulations and proposed changes</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/spoofing-and-phishing-in-polish-law-current-regulations-and-proposed-changes/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/spoofing-and-phishing-in-polish-law-current-regulations-and-proposed-changes/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 23 Feb 2022 11:40:40 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[spoofing and phishing]]></category>
		<category><![CDATA[What is spoofing and phishing]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=4417</guid>

					<description><![CDATA[<p>Spoofing and phishing in Polish law - current regulations and proposed changes</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/spoofing-and-phishing-in-polish-law-current-regulations-and-proposed-changes/">Spoofing and phishing in Polish law &#8211; current regulations and proposed changes</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading"><strong>What is spoofing and phishing?</strong></h2>


<div class="wp-block-image">
<figure class="alignleft size-large is-resized"><img decoding="async" src="https://www.kg-legal.eu/wp-content/uploads/2016/12/pay-per-view.jpg" alt="" style="width:315px;height:auto"/></figure></div>


<p>Both spoofing and phishing are methods of fraud using telecommunications and the Internet, but they differ in how they are used. Spoofing involves broadly impersonating the IP address of another device, telephone number, email address or DNS server. Everything is camouflaged in such a way that the identification of the real user or caller is impossible. The easiest to recognise is email spoofing. The content of the message sent by someone impersonating a chosen e-mail address indicates the intention of spoofing confidential information from the addressee of the message. Phone number spoofing is carried out using easily accessible websites that, for a fee, allow you to make a call from any phone number and change the voice or convert the text into a voice that the person answering the phone will hear. Detection of such spoofing is only possible after the fact, when checking the billing of the number called and impersonated. IP address and DNS server spoofing is the most difficult to detect, as it may differ only slightly from the real one. The essence of phishing is reflected in its pronunciation, which is similar to the word &#8220;fishing&#8221;. It consists in preparing a &#8220;lure&#8221; for the user, e.g. by means of a link sent in an e-mail message, SMS or via instant messenger, and then either installing malicious software on the device or phishing for login data. The fraudster may impersonate e.g. a bank, government agency, courier company or a friend of the victim. Phishing emails are usually designed to look as authentic as possible. One form of phishing is spear-phishing, which involves a targeted attack on, for example, a specific company and impersonation of a business partner.</p>



<h2 class="wp-block-heading"><strong>Polish legal regulations on spoofing and phishing</strong></h2>



<span id="more-4417"></span>



<p>There are no provisions in Polish law that would directly prohibit spoofing and phishing, although this does not mean that such behaviour is not punishable on the basis of the Polish Penal Code. Spoofing, as impersonating someone else by its very nature, meets the requirements of the prohibited act pursuant to Article 190a § 2 of the Polish Penal Code: <em>whoever, by impersonating another person, uses that person&#8217;s image, other personal data or other data by means of which that person is publicly identified, in order to cause material or personal damage to that person</em>. Phishing is punishable under Article 267 §1 of the Polish Penal Code: <em>Whoever without authority gains access to information not intended for them by opening a closed letter, by connecting to a telecommunications network or by breaking or bypassing electronic, magnetic, IT or other specific security thereof</em>. Both phishing and spoofing may also constitute an offence under Article 287 §1 of the Polish Penal Code: <em>Whoever, in order to gain a material benefit or to cause damage to another person, without authorisation, affects the automatic processing, collection or transmission of IT data or changes, deletes or introduces a new record of IT data</em>. Naturally, these are the basic provisions, features of which are fulfilled by phishing and spoofing, as they may be in conjunction with other provisions of the Polish Penal Code, such as unlawful threat (Article 190 §1), forcing to behave, refrain from or cease in a specific manner (Article 191 §1), defamation (Article 212 §1 and 2), insult (Article 216 §1 and 2), false report of a danger (Article 224a §1 and 2), appropriation of the function of a public official (Article 227), destroying, damaging, deleting, altering or obstructing access to computer data (Article 268a), destroying, damaging, deleting, altering or obstructing access to sensitive computer data (Art. 269), interference with the operation of an IT system, data communications system or a data communications network (Art. 269a), theft of a computer programme (Art. 278 §2) and many other crimes that may be committed in relation to spoofing and phishing. The legal grounds for punishing spoofing and phishing are numerous in Polish law, depending on the specific action of the perpetrator and its purpose. However, a problem arises at the stage of detecting such offences and holding their perpetrators criminally liable. Spoofing and phishing are often of cross-border nature &#8211; the perpetrator of the crime using them is often located abroad. Moreover, the perpetrators are difficult to detect due to the masking methods used: creating intermediary middlemen, often unaware of the procedure, masking their identity or using another person&#8217;s identity and high dynamism in creating e.g. new websites.</p>



<p><strong>Bank liability for inadequate protection against spoofing and phishing</strong></p>



<p>The Act of 19 August 2011 on payment services (Journal of Laws 2011, No. 199, item 1175, with subsequent amendments) is relevant under Polish law from the perspective of the bank&#8217;s liability for inadequately protecting clients against such practices. The first obligation, arising from Article 40 of this act, is related to securing the executed transaction by means of various established methods of verification. Consent given by the payer before execution of the transaction is a prerequisite for the transaction to be deemed authorised. The payer can also hold the transaction until the payer&#8217;s provider receives an order to execute it. If there is an unauthorised transaction from the payer&#8217;s account, the bank is obliged under Article 46 to refund the amount that was debited from the payer&#8217;s account. There is an exception if the bank has a reasonable suspicion of fraud, in which case it will report this to the law enforcement authorities. In addition, the aforementioned act in article 45 point 1 requires the bank to prove that the transaction was authorised. Thus, if the customer exercised due diligence and nevertheless became a victim of fraud, the safeguards are deemed insufficient and the bank is held liable.</p>



<h2 class="wp-block-heading"><strong>Regulations under European Union law</strong></h2>



<p>European law also refers to spoofing and phishing. The law currently in force in this area is Directive (EU) 2019/713 of the European Parliament and of the Council of 17 April 2019 on combating fraud and counterfeiting of non-cash means of payment, replacing Council Framework Decision 2001/413/JHA. This Directive sets out requirements for Member States to prevent and combat crimes related to non-cash means of payment. Under Article 6 of this Directive, Member States are required to penalise conduct which consists in <em>performing or causing a transfer of</em> <em>money, monetary value or virtual currency and thereby causing an unlawful loss of property for another person in order to make an unlawful gain for the perpetrator or a third party, punishable as a criminal offence when committed intentionally without right, hindering or interfering with the functioning of an information system or without right, introducing, altering, deleting, transmitting or suppressing computer data</em>. The regulation in this article therefore refers to spoofing and phishing, although it does not name them explicitly. In Article 9, the Directive sets out the minimum criminal penalties to be applied in the criminal laws of Member States for the offences committed by natural persons set out in the Directive. The Directive obliges Member States to introduce provisions that punish not only natural but also legal persons. Article 10 of the Directive establishes the requirement that Member States&#8217; legislation create the conditions for a legal person to be liable for an offence committed for its benefit <em>by any person, acting either individually or as part of a body of the legal person, and having a leading position within the legal person, based on one of the following: a power of representation of the legal person, an authority to take decisions on behalf of the legal person or an authority to exercise control within the legal person. </em>A legal person is also liable where the lack of supervision or control, by one of those persons employed by the legal person, has made it possible for a person under its authority to commit one of the offences listed in the Directive. Liability of a legal person shall not exclude liability of a natural person who has committed such an offence.</p>



<h4 class="wp-block-heading"><strong>Direction and potential for change to reduce spoofing and phishing</strong></h4>



<p>One of the key methods of combating phishing and spoofing is to make bank customers in particular aware of the methods of fraudsters who use spoofing and phishing to defraud them. Widespread information campaigns and ongoing alerts on identified attacks are designed to warn potential victims and encourage people who have already been victims of spoofing or phishing to report the crime to law enforcement authorities. The Polish authorities are also taking steps to combat these harmful phenomena. One of them is the establishment, under the Act of 17 December 2021 on amending certain acts in connection with the establishment of the Central Bureau for Combating Cybercrime (Journal of Laws 2021, item 2447), of a special body to combat cybercrime &#8211; the Central Bureau for Combating Cybercrime as an organisational unit of the Polish Police. In January 2022, it was announced that changes would be presented in the Polish ICT sector to counteract crimes using spoofing and phishing, but these were not yet presented.</p>



<p><strong>Sources:</strong></p>



<ol class="wp-block-list">
<li><a href="https://www.avast.com/pl-pl/c-spoofing" target="_blank" rel="noreferrer noopener">https://www.avast.com/pl-pl/c-spoofing</a></li>



<li><a href="https://niebezpiecznik.pl/post/spoofing-rozmow-telefonicznych/" target="_blank" rel="noreferrer noopener">https://niebezpiecznik.pl/post/spoofing-rozmow-telefonicznych/</a></li>



<li><a href="https://www.gov.pl/web/baza-wiedzy/czym-jest-phishing-i-jak-nie-dac-sie-nabrac-na-podejrzane-widomosci-e-mail-oraz-sms-y" target="_blank" rel="noreferrer noopener">https://www.gov.pl/web/baza-wiedzy/czym-jest-phishing-i-jak-nie-dac-sie-nabrac-na-podejrzane-widomosci-e-mail-oraz-sms-y</a></li>



<li><a href="https://www.avast.com/pl-pl/c-phishing">https://www.avast.com/pl-pl/c-phishing</a></li>



<li><a href="https://rpms.pl/phishing-na-czym-polega-i-jak-mu-przeciwdzialac/" target="_blank" rel="noreferrer noopener">https://rpms.pl/phishing-na-czym-polega-i-jak-mu-przeciwdzialac/</a></li>



<li><a href="https://www.komputerswiat.pl/aktualnosci/bezpieczenstwo/rzad-zapowiada-nowe-przepisy-do-walki-z-oszustami-w-sieci-chodzi-o-spoofing-i/demsmk0" target="_blank" rel="noreferrer noopener">https://www.komputerswiat.pl/aktualnosci/bezpieczenstwo/rzad-zapowiada-nowe-przepisy-do-walki-z-oszustami-w-sieci-chodzi-o-spoofing-i/demsmk0</a></li>



<li>Act of 19 August 2011 on payment services (<a>Journal of Laws </a>2011, No. 199, item 1175, with subsequent amendments)</li>



<li>Act of 6 June 1997. &#8211; Penal Code (Journal of Laws of 2021, item 2345)</li>



<li>Directive (EU) 2019/713 of the European Parliament and of the Council of 17 April 2019 on combating fraud and counterfeiting of non-cash means of payment, replacing Council Framework Decision 2001/413/JHA</li>



<li>Act of 17 December 2021 on amending certain acts in connection with the establishment of the Central Bureau for Combating Cybercrime (Journal of Laws 2021 item 2447)</li>
</ol>



<p></p>



<div class="wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex">
<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://www.kg-legal.eu/" target="_blank" rel="noreferrer noopener">go to the home page of KIEŁTYKA GŁADKOWSKI LEGAL</a></div>



<div class="wp-block-button"><a class="wp-block-button__link wp-element-button" href="https://www.kg-legal.eu/info/" target="_blank" rel="noreferrer noopener">go to the main page of this information service of KIEŁTYKA GŁADKOWSKI LEGAL</a></div>
</div>


<ul class="wp-block-rss"><li class='wp-block-rss__item'><div class='wp-block-rss__item-title'><a href='https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/'>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a></div></li><li class='wp-block-rss__item'><div class='wp-block-rss__item-title'><a href='https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/influencer-marketing-in-minecraft-and-consumer-law/'>Influencer Product Placement in Open-World Games and Competition and Consumer Protection Law</a></div></li><li class='wp-block-rss__item'><div class='wp-block-rss__item-title'><a href='https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/'>Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</a></div></li><li class='wp-block-rss__item'><div class='wp-block-rss__item-title'><a href='https://www.kg-legal.eu/info/kg-legal-news/partner-of-kg-legal-kieltyka-gladkowski-contributes-to-the-2026-edition-of-the-world-justice-project-rule-of-law-index/'>Partner of KG Legal KIELTYKA GLADKOWSKI contributes to the 2026 edition of the World Justice Project Rule of Law Index®</a></div></li><li class='wp-block-rss__item'><div class='wp-block-rss__item-title'><a href='https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/'>Drone Warfare</a></div></li></ul><p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/spoofing-and-phishing-in-polish-law-current-regulations-and-proposed-changes/">Spoofing and phishing in Polish law &#8211; current regulations and proposed changes</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/spoofing-and-phishing-in-polish-law-current-regulations-and-proposed-changes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
