Skip to content Skip to footer

Report an incident

Report a security incident – quickly and effectively

If you have become a victim of an attack, please contact us. We will provide you with assistance and all the necessary advice. Follow the instructions below.

security@agh.edu.pl

Contact us

Report an attack

Find out how to report

Change your password 

Find out how to change it

Secure your documents

Find out how to secure


1. Report an attack to us

Anyone who becomes aware of an incident is required to report it to the Information Security Centre (CBI). To report security incidents, please contact us via one of the channels listed below.

Find out what the notification should contain

By phone

 +48 885 850 762  between 8:00 and 16:00

In person

Władysława Reymonta 23, 30-059 Kraków (D-8), 7th floor, room 718B 
between 8:00 and 16:00

Are you able to provide an initial assessment of the incident?

Please inform the appropriate department:

  • IT Helpdesk – in case you detect irregularities in central IT systems, e.g., email accounts, university-wide services
  • System Administrator - if irregularities are detected in the operation of a local IT system (i.e., concerning one unit or department of the university) 
  • Network Administrator - in case of detection of irregularities in the operation of the Unit's network
  • Local Information Security Administrator or Data Protection Officer - in case there is a suspected breach of personal data security

List of Local Information Security Officers

  • Security, law enforcement or emergency services -when there is a physical threat or a threat to human health and life.

Contact AGH Campus Security

2. Change password to account

If the attack has exposed information such as the username and password for your email account (or any other account), you should change them as soon as possible. In the case of email, this is done through the poczta.agh.edu.pl website by selecting Settings => Password from the top menu.

Note: Do not use any links provided in the fraudulent message.

3. Invalidate disclosed documents

If the attack involved your identity documents (e.g., ID card, passport, driver's license) and you have provided the attackers with their details or photographs, you should invalidate or suspend them.

Invalidate your ID card

Also, inform your bank about the loss of the document. If you have disclosed payment card details or made payments to the attackers' account, notify your bank as soon as possible. This will serve as the basis for a complaint and the possible recovery of your money.

We also recommend blocking your PESEL number.

Block your PESEL


What the notification should contain?

  • Name, email and, if possible, business phone number of the reporting person
  • A detailed description of the incident - what happened, what are the consequences, whether the security of personal data may have been compromised (e.g., through data leakage), the scale of the incident.
  • How the incident was detected.
  • How the breach may have occurred (if the notifier has such knowledge).

If the message needs to be encrypted, you can use our PGP key:

Download the PGP key

If you report an email to us, we recommend saving the suspicious message in .eml format to facilitate analysis. You can do this through the "Save As" option available in most email clients. Then please send us this message as an attachment.

In the upper right corner (above the message) More => Save As

Right click on the message in question => Save as... 

In the middle, upper right corner of the message window, click the "message with note" sign => "Forward as attachment"

Click on the gear wheel in the top menu => Download (.eml)

We wish to inform you that the organisation does not have a bug bounty programme in place.

Stopka