# Dlaczego dajesz się zhakować? | Kamil Porembiński | TEDxKoszalin

Source: https://www.youtube.com/watch?v=KRfBfyO4BhQ
Recap page: https://rapidrecap.app/video/KRfBfyO4BhQ
Generated: 2026-01-14T16:09:31.165+00:00

---
## Quick Overview

Kamil Porembiński argues that users are easily hacked because they fail to apply basic cybersecurity hygiene, such as checking URLs for phishing attempts (like "pekao.pl-pomoc.net" instead of "pekao24.pl"), using strong passwords (like "SmażęPierogiW2Piramidach" instead of "8080"), and failing to recognize social engineering tactics used in scams involving fake pleas for help or fake job offers.

**Key Points:**
- Users are frequently phished because they often ignore crucial warning signs, such as subtle differences in URLs (e.g., "pekao.pl-pomoc.net" vs. the real "pekao24.pl").
- The speaker demonstrates that weak passwords, like the numerical "8080," are easily guessed, contrasting them with strong, long passwords like "SmażęPierogiW2Piramidach!" which incorporate complexity.
- Scammers use real-time marketing (like responding to current events such as floods) and social engineering tactics, often exploiting human empathy by posting fake missing child alerts or pleas for financial help.
- The speaker warns against sharing private medical data (like laboratory results) online, showing an example where data was leaked from a Polish anti-doping agency (POLADA).
- Companies are also targeted; a marketing firm's internal file structure, complete with sensitive department names, was exposed online due to poor password hygiene.
- The presentation concludes by urging the audience to adopt better cybersecurity hygiene, emphasizing that simple steps like checking URLs and using strong, complex passwords are essential protections against common attacks.

![Screenshot at 00:05: Kamil Porembiński begins his TEDx Koszalin talk with the title slide "Dlaczego dajesz się zhakować?" \(Why do you let yourself get hacked?\), immediately setting the theme of personal responsibility in cybersecurity.](https://ss.rapidrecap.app/screens/KRfBfyO4BhQ/00-00-05.jpg)

**Context:** Kamil Porembiński delivered this TEDxKoszalin talk titled "Dlaczego dajesz się zhakować?" (Why do you let yourself get hacked?) to educate the audience on common cybersecurity vulnerabilities stemming from human error and lack of awareness. The talk uses several examples of real-world scams, including phishing attempts, social engineering exploits, and data breaches, to illustrate how easily individuals and even organizations can fall victim to cyberattacks if they neglect basic digital safety practices.

## Detailed Analysis

Kamil Porembiński's talk focuses on why people easily fall victim to cyberattacks, attributing the problem primarily to poor personal cybersecurity hygiene rather than solely technological failures. He starts by highlighting the frequency of scams, citing that 36 people lose access to their Facebook or Instagram accounts every 30 seconds in Poland. He illustrates phishing by comparing the real bank URL ("pekao24.pl") with a fake one ("pekao.pl-pomoc.net"), noting that many users click the fraudulent link because they do not scrutinize the URL, especially when under pressure or in a hurry. Porembiński then addresses password strength, contrasting the weak password "8080" with a strong, long one like "SmażęPierogiW2Piramidach!" (I fry pierogi in two pyramids!), noting that longer, complex passwords are significantly more secure. He moves on to social engineering, showing examples of fake posts regarding missing children or false pleas for money following real events like floods, which exploit people's good nature, leading to widespread sharing and potential account compromise. He also points out that companies are vulnerable, showing an example of leaked internal documents from a security firm that contained passwords and confidential department structures. Finally, he touches upon the data leak from POLADA (Polish Anti-Doping Agency) as an example of sensitive data exposure. His overall message is that while cybercriminals use advanced technology (like real-time marketing to exploit current events), the primary defense lies in basic user vigilance, such as carefully checking URLs and using strong, unique passwords.

### Introduction & Statistics

- Setting the stage with alarming statistics, noting 36 people lose access to Facebook/Instagram accounts every 30 seconds
- Presenting the core question: Why do users allow themselves to be hacked?

### Phishing Awareness

- Demonstrating the difference between a legitimate bank URL (pekao24.pl) and a phishing URL (pekao.pl-pomoc.net)
- Highlighting that users often fail to check the URL, especially when rushed.

### Password Strength

- Contrasting weak passwords (like '8080') with strong ones ('SmażęPierogiW2Piramidach!')
- Explaining that longer passwords with varied character types are fundamentally safer.

### Social Engineering Scams

- Showing examples of fake pleas for help (e.g., missing child in Warsaw flood) designed to trigger emotional responses and widespread sharing
- Illustrating how these scams trick users into clicking malicious links.

### Enterprise Vulnerabilities

- Revealing leaked credentials from a security firm (showing file directories like 'Dział Raporty' and 'Dział IT') and the POLADA doping data leak
- Emphasizing that even organizations with security teams suffer from poor employee hygiene.

### Conclusion & Actionable Advice

- Summarizing that education (Digital Education) is key
- Urging the audience to use long, complex passwords and to always verify URLs before interacting with links.

![Screenshot at 00:02: Display of sponsors for the TEDx Koszalin event, including Globmetal and Q4 Windows.](https://ss.rapidrecap.app/screens/KRfBfyO4BhQ/00-00-02.jpg)
![Screenshot at 00:05: Title slide for Kamil Porembiński's talk: "Dlaczego dajesz się zhakować?" \(Why do you let yourself get hacked?\).](https://ss.rapidrecap.app/screens/KRfBfyO4BhQ/00-00-05.jpg)
![Screenshot at 00:11: The timer displays '18', indicating the standard time limit for TED talks, while Porembiński begins speaking on stage.](https://ss.rapidrecap.app/screens/KRfBfyO4BhQ/00-00-11.jpg)
![Screenshot at 00:36: Slide showing a silhouette of a hacker at multiple monitors with the text: "Jestem ten DOBRY ;-\) \(I am the GOOD one ;-\)", illustrating the deceptive nature of some cyber threats.](https://ss.rapidrecap.app/screens/KRfBfyO4BhQ/00-00-36.jpg)
![Screenshot at 01:08: Slide comparing three entities labeled 'GOŁĄB' \(Pigeon\), 'GOŁĄB ZNANEJ MARKI' \(Brand Name Pigeon\), and 'JASZCZOMB' \(a phonetic joke on the name Jaszczomb, likely referring to a public figure\), used to illustrate concepts of comparison and recognition.](https://ss.rapidrecap.app/screens/KRfBfyO4BhQ/00-01-08.jpg)
