< Back to all clusters
[TECHNOLOGY] · Poland · 2 sources

Polish Data Protection Office warns of inadequate SMS MFA and risks to children online

The Polish Data Protection Office (UODO) has warned that SMS‑based codes are no longer sufficient for two‑factor authentication. According to UODO head of the Department of Control and Violations, Andrzej Zieliński, attackers are increasingly stealing session tokens and using Adversary‑in‑the‑Middle techniques to bypass MFA, gaining access to email, file‑sharing services, and communication tools, and facilitating Business E‑mail Compromise attacks. The office advises limiting the use of SMS codes, adopting hardware security keys (U2F), restricting device access, limiting logins from unusual locations and shortening token lifetimes.

At a recent gala, UODO deputy head Agnieszka Grzelak highlighted the danger that children and adolescents face online, noting they often cannot recognise the risks of over‑sharing personal data. She stressed the need for education programmes such as “Your data – your case” to teach young people about privacy, AI, disinformation and age‑verification measures. Grzelak warned that authorities have too often dismissed incidents involving minors, urging systemic regulation and practical school‑based projects to build responsible digital habits.