How to report phishing to CERT Poland

Send the suspect SMS to 8080, and report the page or message via official channel. The request does not replace account security.

2 min readFor execution: 5–10 minutes per application
In this guide

You do not have to visit a suspicious website to report it. Giving information to the official response team helps with risk analysis, but does not guarantee immediate blocking of the link or recovery of lost money.

Suspect SMS

Use the message transfer function and send it unchanged content to the number 8080, indicated by CERT Polska. Do not respond to the SMS and do not open the link for “confirmation” of fraud.

If your phone does not allow you to send a message this way, check the current notification options in the official CERT knowledge database. An application number is not a channel for blocking a bank card or helping you recover a password.

Page or email

Forms can be found in the service Incident.cert.plYou can also send a suspicious email in accordance with CERT instructions to the address cert@cert.plProviding original information about the news helps determine its origin.

Describe when the message was received and what the request relates to. Do not enter your own password, 2FA codes or full payment data. Check the screenshots before attaching. If the form asks for additional data, read its instructions and processing rules.

Please also report on the platform

Use the phishing notification button in the mail or the mechanism for reporting messages and accounts on the social site. If the matter concerns equipment or business account, please inform the administrator in accordance with the organisation procedure.

Do not send an active link to your friends without context. By warning them, describe the pattern of the request and the way in which the case is independently checked. Do not publish the data of the person who is impersonated as a fraud.

If the incident already has effects

After entering a password or accepting an unknown login, first secure your account. If you have unauthorized transactions, contact the bank directly. The application to CERT does not invalidate the session, does not change the passwords and does not replace the report to the relevant services.

Choose your situation in post-phishing response planto go through appropriate first actions without entering passwords, codes or payment data.