Warsaw, Poland – A Polish prosecutor’s office has formally indicted Michał Dworczyk, a prominent member of the Law and Justice (PiS) party and currently a Member of the European Parliament, on charges related to the so-called “afera mailowa” – the email affair. The indictment, filed on Wednesday, March 11, 2026, alleges that Dworczyk failed to fulfill his duties regarding the protection of classified information while serving in key government positions. This development marks a significant escalation in a case that has raised concerns about security protocols and the handling of sensitive data within the Polish government.
The charges stem from allegations that Dworczyk used a private, uncertified email account to conduct official government business between March 1, 2017, and June 8, 2021. During this period, he held the positions of Deputy Minister of National Defence (until December 18, 2017) and then Chief of the Chancellery of the Prime Minister (from December 19, 2017, to June 8, 2021). Prosecutors claim this practice compromised the security of state information, as the private account allegedly contained classified data pertaining to national defense, security services, economic matters, and the country’s response to the COVID-19 pandemic. The case highlights the ongoing scrutiny of data security practices among Polish officials and the potential risks associated with using non-secure communication channels for sensitive government matters.
Indictment Details: Allegations of Negligence and Obstruction
According to a statement released by the Warsaw District Prosecutor’s Office, Dworczyk is accused of violating Article 231 § 1 of the Polish Penal Code, which concerns the negligent handling of classified information. The indictment specifically cites failures to comply with the Act of August 5, 2010, on the Protection of Classified Information, as well as internal regulations governing security protocols within the Prime Minister’s Chancellery. These regulations include the Security Policy of the Prime Minister’s Chancellery dated October 27, 2015, the Information Security Policy, and the Regulation No. 12 of the Head of the Prime Minister’s Chancellery dated September 14, 2012, concerning the organization and functioning of the Secret Chancellery.
However, the charges extend beyond simply using an insecure email account. Prosecutors also allege that Dworczyk attempted to obstruct the investigation following the public disclosure of the leaked emails in June 2021. The indictment claims that Dworczyk instructed an unnamed individual to permanently delete incoming phishing emails and associated metadata from his private email account. Prosecutors argue this action was an attempt to hinder the identification of the perpetrator who compromised his account and to conceal evidence. This alleged obstruction of justice adds a further layer of seriousness to the charges against the former minister.
The “Email Affair” and its Political Fallout
The “afera mailowa” first surfaced in 2021, when a large volume of emails originating from Dworczyk’s private email account were leaked to the public. The content of these emails sparked widespread controversy, with critics alleging that they revealed improper influence peddling and questionable decision-making within the government. The leaks prompted investigations by both law enforcement agencies and parliamentary committees. The incident quickly became a major political issue, fueling opposition attacks against the then-ruling PiS party and raising questions about the security of government communications.
Following the initial reports, Dworczyk stated that he had informed the relevant security services about the hacking of his email account and his wife’s social media accounts. He maintained that the leaked emails did not contain any classified or sensitive information. However, subsequent investigations revealed the presence of classified data within the compromised account, leading to the formal criminal investigation and, the indictment. The Polish news outlet Polsat News reported that the emails contained information related to defense, security, telecommunications security, economic affairs, the COVID-19 response, and international relations.
Potential Penalties and Next Steps
If convicted, Dworczyk faces a potential prison sentence of between three months and five years. The case is now set to proceed to the Warsaw-Śródmieście District Court, where a trial date will be determined. The proceedings are expected to be closely watched, not only by the Polish public but also by observers interested in the broader implications for data security and accountability within government. The trial could set a precedent for how Polish authorities handle similar cases involving the misuse of private communication channels for official purposes.
Legal experts suggest that the prosecution will focus on demonstrating that Dworczyk knowingly disregarded established security protocols and that his actions created a significant risk to national security. The defense is likely to argue that Dworczyk was the victim of a hacking attack and that he took appropriate steps to mitigate the damage. The outcome of the trial will depend on the evidence presented by both sides and the court’s interpretation of the relevant laws and regulations.
Broader Implications for Data Security in Poland
The Dworczyk case underscores the growing importance of cybersecurity and data protection in the modern era. Governments around the world are facing increasing threats from cyberattacks and data breaches, and the require for robust security measures is more critical than ever. The incident has prompted calls for stricter regulations governing the use of private communication channels by government officials and for increased investment in cybersecurity infrastructure.
The Polish government has already taken some steps to address these concerns, including issuing new guidelines on the use of secure communication tools and providing cybersecurity training to government employees. However, critics argue that more needs to be done to ensure that sensitive information is adequately protected. The Dworczyk case serves as a stark reminder of the potential consequences of lax security practices and the importance of holding individuals accountable for their actions.
The indictment of Michał Dworczyk represents a significant development in the “afera mailowa” saga. As the case moves forward, it will undoubtedly continue to generate public debate and scrutiny of data security practices within the Polish government. The next scheduled action is the setting of a trial date by the Warsaw-Śródmieście District Court, a development that will be closely monitored by legal experts and the public alike. We encourage readers to share their thoughts and perspectives on this important case in the comments below.
Related reading