Courts, Hospitals, Airports Hacked: Is Your SME Next?

Courts, Hospitals, Airports Hacked: Is Your SME Next? — featured image

by

Your Business Has the Same Weak Spot as Those Hacked Polish Courts

Imagine a burglar who doesn’t need to break a window. Instead, they walk through a back door that the previous owner never bothered to lock. That is the situation at the heart of a new cybersecurity report from Poland, and it carries a direct warning for every small and medium business owner in Malaysia. A pair of security researchers took a look at their country’s public-facing websites — the ones used by courts, hospitals, airports, and government offices — and discovered more than 10,000 affected public entities. Yes, you read that correctly: 10,000. And it wasn’t because attackers were using exotic new tricks. The doors were simply left open.

What Happened

At the Def Con cybersecurity conference in Las Vegas, researchers Robert Kruczek and Kamil Szczurowski presented the results of what they described as a patriotic effort: scanning Poland’s digital public square to understand how vulnerable it really was. What they uncovered was the digital equivalent of a building inspection failing at almost every checkpoint. Across 250,000 websites, they found security flaws linked to airports, hospitals, and government offices.

The most surprising part was how ordinary the mistakes were. The researchers found critical vulnerabilities in a content management system called Pad CMS, which let them access more than 300 public websites without even entering a password. The reason? The software had reached its end of life, and the developer had stopped supporting it. Another bug gave the pair access to the websites of two-thirds of Poland’s judiciary — about 245 courts. Their attempts to report the problems were often met with a shrug; some vendors described the bug reports as “inconveniences.” Worse, there were no bug bounties and no clear channels to report vulnerabilities, making it harder for researchers — or anyone else — to do the right thing.

Poland is not new to cyber trouble. The report notes a wave of suspected Russian-linked attacks aimed at the country’s energy and water providers, and some of those attacks succeeded by exploiting weak cybersecurity. Sound familiar? It should.

Why This Matters for Malaysian SMEs

If you run a small or medium business in Malaysia, your first instinct might be to scroll past this as “not my problem.” But this story is exactly your problem, for three reasons.

First, the vulnerabilities were not in exotic technology — they were in everyday content management systems and forgotten outdated software. Think about your own business. How old is your point-of-sale system? Is your booking platform still maintained by the original developer? Do you have an old customer database that nobody wants to migrate because it’s “still working”? Every one of those is a potential back door. In Poland, the vulnerable systems belonged to public services. In Malaysia, they could just as easily be yours.

Second, the report highlights a communication gap. When end-of-life products break, vendors don’t want to hear about it. You cannot rely on your software suppliers to keep you informed about security flaws. As an SME, you likely don’t have a Chief Information Security Officer or a dedicated IT team. That means you need to build your own simple version of that process: keep a list of every piece of software your business depends on, check whether each one is still supported, and set a date to review it. Even a spreadsheet with a monthly calendar reminder is better than nothing.

Third, understand that your security affects people beyond your own front door. Many Malaysian SMEs supply goods, services, or digital tools to government agencies, hospitals, and larger corporations. Imagine an SME that manages appointment scheduling for a clinic, or a supplier that handles invoices for a government department. If your website is compromised, your clients are compromised too — and they will remember who opened the door. Acting now isn’t an IT luxury; it’s a business survival requirement.

The Bigger Picture

What the Polish researchers found is not unique to Poland. Public infrastructure in many countries, including Malaysia, runs on software kept alive beyond its support lifecycle because replacing it seems disruptive. But the longer you wait, the more exposed you become. The researchers’ motivation offers an important lesson: the person most likely to protect your business is you, not some faraway software developer. When the Polish duo said the effort was ultimately worthwhile because “we are a little bit more safe,” they were describing the power of exposure — the first step to fixing a problem is knowing it exists.

“Some bugs were incredibly easy to exploit but were not always taken seriously, with some vendors describing the bug reports as inconveniences.” — Robert Kruczek and Kamil Szczurowski, Def Con 2026

So what can you do this week? Start by treating your digital tools as physical assets. Would you leave your office at night without checking that the windows are closed? Probably not. The same logic should apply to your website login page, your inventory system, and any plugin you have forgotten you even installed. The solutions don’t need to be complicated — regular updates, strong passwords, and a clear plan for anything that reaches its end of life can substantially reduce the risk. If you are working with an automation partner like AutoRunBiz, ask them directly how they handle legacy software and unsupported systems, because automation only helps you if it doesn’t add another neglected door to your building.

What happened in Poland What you should check in your SME
10,000+ public entities had websites with security flaws List every digital system your business runs — websites, booking tools, databases
250,000 websites were at risk Check if each system is still supported by its vendor and has recent updates
Pad CMS was end-of-life and unpatched Replace or isolate any software that is no longer maintained
No bug bounties or reporting channels Set up your own reporting route — even a simple alert list for security news
Vendors treated bug reports as “inconveniences” Ask your vendors for their security contact and their patch policy before you sign

The Polish research proves that cyberattacks don’t need to be clever. They need one neglected door, one forgotten system, or one bug report that was brushed aside. As a Malaysian SME owner, you have the power to make sure that doesn’t happen to you — and the research gives you a reason to start right now.

Ready to Streamline Your Operations?

Technology moves fast. Your operations should keep up. AutoRunBiz builds AI systems that run your daily workflows — from WhatsApp order capture to accounting. Book a free 15-min ops audit →