
Polish deputy minister's WhatsApp hijacked in fake scholarship vote scam
Attackers took over the WhatsApp account of Poland's deputy justice minister Arkadiusz Myrcha and sent contacts a link to a bogus scholarship vote, prompting a nationwide cybersecurity alert on Sunday.
How the scam unfolds
The attack begins when criminals gain control of a WhatsApp account. They then send messages to the victim's contacts, asking them to vote for a child named Zofia in a contest offering a scholarship. The message includes a link. If the recipient clicks, they are taken to a page that requests "verification" through WhatsApp. This step requires scanning a QR code or entering a verification code sent to their device. By completing it, the user unknowingly pairs the attacker's device with their own WhatsApp account, granting the criminal full access. The hijacked account is then used to send the same message to all contacts, rapidly widening the scam. Because the messages appear to come from a trusted friend or colleague, they are particularly effective. The technique is a classic form of phishing, where attackers exploit a trusted guise to trick victims into revealing sensitive information or installing malware.
Criminals are taking over WhatsApp accounts and, in the name of their owners, sending messages about a supposed contest and asking for a vote. The condition for voting is 'verification' via the WhatsApp account. Fraudsters gain access to our account by pairing their device with it, either by scanning a fake QR code in the app or entering a verification code.
Myrcha's account compromised
On Sunday, 2 August 2026, the WhatsApp account of Arkadiusz Myrcha, Poland's deputy minister of justice and a secretary of state in the Ministry of Justice, was taken over. Messages with the fake voting link were sent to his contacts. Myrcha, a member of the Civic Coalition, quickly posted a warning on X. Journalist Szymon Jadczak of Wirtualna Polska noted that this was another case of spam with a clickable link being sent from accounts of people holding important state functions. Screenshots of the suspicious message were also shared by publicist Wojciech Mucha.
If someone on WhatsApp got a message from me with a voting link, please don't click. It's a virus!
The fraudulent message, as reported by Fakt24, read: "Hi! Can you vote for Zofia? She's my friends' daughter, and the main prize is a scholarship for free education. It's really important to her! Thank you in advance!" The link directed recipients to a page designed to harvest credentials or install malware.
Official response and user guidance
CERT Polska, the national computer emergency response team operating within the NASK research institute, issued a public alert on X later that day. The warning was amplified by Karolina Gałecka, spokesperson for the Ministry of Interior and Administration, and by the Prime Minister's office. CERT explained that the only way to sever the attackers' access is to immediately unpair all added devices in the WhatsApp settings. Users were also advised to report suspicious messages and websites through the CERT website (incydent.cert.pl) or via the mObywatel app's "Bezpiecznie w sieci" (Safe online) service. Suspicious SMS messages can be forwarded to the toll-free number 8080.
- Scam messages with fake voting link sent from compromised WhatsApp accounts, including that of deputy minister Arkadiusz Myrcha.
- Myrcha posts warning on X, telling recipients not to click the link.
- CERT Polska issues public alert describing the scam and advising users to unpair devices.
Reactions and earlier warnings
The incident triggered a wave of ironic comments on social media. One user wrote, "Incredible, the deputy justice minister is spreading viruses. A cardboard state!" MP Olga Semeniuk-Patkowska shared Myrcha's post and remarked, "These people 'care' about Poland's security." Another journalist, Jarek Jakimczyk, displayed a message he said he received from a well-known figure in diplomacy, containing an invitation to a WhatsApp group with a suspicious link. The episode follows a broader pattern. In June 2026, the Government Plenipotentiary for Cybersecurity had warned of a campaign in which cybercriminals impersonated high-ranking state officials on WhatsApp and Signal, using publicly available photos and data to make the messages appear authentic. That earlier alert highlighted the same technique of exploiting trusted contacts to bypass suspicion.


