Dark Web Informer@DarkWebInformer
‼️🇵🇱 Nowa Nadzieja ("New Hope"), the Polish far-right political party led by Sławomir Mentzen and a member of the Konfederacja parliamentary coalition, has allegedly suffered an unauthorized access of its internal membership infrastructure for the third time, with a full member database and internal documents published on a popular cybercrime forum.
⠀
‣ Threat Actor: poisonivy3
‣ Category: Political Party Data Breach / Member Database Leak
‣ Victim: Nowa Nadzieja (New Hope) / Konfederacja
‣ Industry: Politics / Political Parties
⠀
Nowa Nadzieja is the successor to the KORWiN party, chaired since 2022 by Sławomir Mentzen. It holds seven Sejm seats through the Konfederacja Wolność i Niepodległość coalition, and Mentzen placed third in the 2025 Polish presidential election with roughly 15 percent of the first round vote. The party is widely reported to attract Poland's youngest political membership base, which is directly reflected in the leaked data.
⠀
This is the actor's third claimed intrusion of the same party's infrastructure (tagged "V3"), suggesting the underlying security posture was not remediated after the earlier incidents. The leak allegedly contains:
⠀
▪️ Full member database extracted from the party's internal member management system
▪️ Over 60 internal documents pulled from the same environment
▪️ Screenshots of the internal interface showing member categorization (Kandydaci, Członkowie, Kandydaci do SM, Święta Członkowie, Niczłonkowie SM, Sympatycy) and broadcast tooling
⠀
The exposed fields per member record include:
⠀
▪️ Id and Numer (internal identifiers)
▪️ Nazwisko and Imię (last name and first name)
▪️ Drugie imię (middle name)
▪️ Wiek (age)
▪️ PESEL (11 digit Polish national identification number)
▪️ Płeć (sex)
▪️ Data urodzenia (date of birth)
▪️ E-mail
▪️ Telefon komórkowy and Telefon stacjonarny (mobile and landline)
▪️ Full address: Ulica zamieszkania, Numer domu, Numer lokalu, Kod pocztowy, Miejscowość, Powiat, Region, Okręg, Oddział
▪️ Correspondence address (separate fields)
▪️ Deklaracja, Składka, Akt. (membership declaration, dues, active status)
▪️ Data przyjęcia, Data rezygnacji, Data anulowania (joining, resignation, cancellation dates)
▪️ Notification and confirmation flags
▪️ "Czy uprawnienie prezesa sm" (whether holds a party presidency privilege)
▪️ Blokada tel. kom. (mobile contact block flag)
⠀
The actor also alleges that party staff lack basic phishing resistance and that the technical security of the party's web infrastructure is similarly weak, framing the repeated intrusions as a consequence of inaction between incidents. A limited number of internal documents were reportedly also pulled, with the actor noting that further document exfiltration was not feasible due to server memory constraints.
⠀
Under Polish law and the GDPR, the party, as data controller, is obliged to notify PUODO within 72 hours of becoming aware of a personal data breach affecting natural persons, and to inform affected members directly where the breach is likely to result in a high risk to their rights and freedoms. Given the scope (full PESEL, address, political affiliation, minor status), both thresholds are plainly met.