Full Report
An investigation on a mass Russian drone incursion into Polish air space on Sept. 9 concluded on Oct. 8.
Analysis Summary
# Incident Report: Russian Drone Incursion and Polish Airspace Violation
## Executive Summary
In September 2026, over 30 Russian Gerbera-type drones violated Polish airspace during a mass incursion, with several being intercepted by the Polish military. A subsequent investigation revealed that the drones were equipped with Polish SIM cards to facilitate connectivity, potentially leveraging local telecommunications infrastructure for navigation or command and control. The legal investigation concluded in October 2026 without identifying specific individual perpetrators, leading to a significant shift in Polish military engagement protocols.
## Incident Details
- **Discovery Date:** September 9, 2026
- **Incident Date:** September 9 – September 10, 2026
- **Affected Organization:** Republic of Poland (Armed Forces / Telecommunications Infrastructure)
- **Sector:** Government / Defense
- **Geography:** Poland (Eastern border regions)
## Timeline of Events
### Initial Access
- **Date/Time:** Night of Sept. 9 to Sept. 10, 2026
- **Vector:** Physical Airspace Breach
- **Details:** More than 30 Russian "Gerbera" one-way attack drones crossed from the East into Polish sovereign airspace.
### Lateral Movement
- **Details:** Drones traversed Polish airspace; investigators discovered three Polish SIM cards integrated into the drone hardware, suggesting the use of local cellular networks to maintain signals or relay data.
### Data Exfiltration/Impact
- **Impact:** Violation of national sovereignty and threat to public safety. Potential exploitation of Polish mobile network bandwidth for drone telemetry or navigation.
### Detection & Response
- **Detection:** Polish military radar and visual observation.
- **Response:** The Polish military engaged the targets, successfully downing several drones. A forensic investigation was launched by the District Prosecutor’s Office in Lublin.
## Attack Methodology
- **Initial Access:** Physical breach of border via unmanned aerial vehicles (UAVs).
- **Persistence:** Use of Belarusian LTE networks and repeater stations for cross-border signal stability, transitioning to Polish SIM cards upon entry.
- **Defense Evasion:** Drones hugged the northern border and utilized low-altitude flight paths to evade traditional detection until breach.
- **Discovery:** Reconnaissance of local cellular network availability to facilitate hardware compatibility (SIM cards).
- **Impact:** Airspace violation and potential kinetic threat to civilian/military infrastructure.
## Impact Assessment
- **Financial:** Costs associated with military sorties, ammunition for downing drones, and forensic investigation.
- **Data Breach:** Compromise of local SIM card identifiers; method of acquisition (theft vs. illegal purchase) remains undisclosed.
- **Operational:** Disruption of standard peacetime monitoring; necessity to scramble military aircraft.
- **Reputational:** Highlighted vulnerabilities in visual identification requirements for intercepting threats.
## Indicators of Compromise
- **Network indicators:** Activity from Polish SIM cards originating from non-standard mobile devices (UAV flight controllers).
- **File/Hardware indicators:** Gerbera-type drone wreckage; localized SIM cards found within recovered electronic modules.
- **Behavioral indicators:** Flight paths deviating from standard civilian or military patterns, originating from Belarusian/Russian territory.
## Response Actions
- **Containment:** Kinetic interception (shooting down) of the intruding drones.
- **Eradication:** Forensics on downed hardware to identify origin and technical specifications.
- **Recovery:** Implementation of new military engagement procedures ("Positive Identification" vs. "Visual Identification").
## Lessons Learned
- **Key Takeaways:** Adversaries are increasingly using commercial off-the-shelf (COTS) components, like local SIM cards and LTE networks, to bypass electronic warfare measures and maintain command links.
- **Gaps:** Peacetime engagement rules requiring visual identification caused delays in neutralizing threats.
## Recommendations
- **Procedure Update:** Shift from visual identification to radar-based "positive identification" to authorize immediate neutralizations of intruders.
- **Telecom Monitoring:** Work with telecommunications providers to identify and flag SIM card activity that exhibits high-speed, high-altitude, or non-standard mobility patterns.
- **Border Defense:** Increase the density of repeater jamming and signal intelligence along the eastern border to disrupt drone-to-cell-tower communications.