Ghostwriter Gmail and 2FA phishing targets Poland
CERT Polska reports an intense UNC1151/Ghostwriter Gmail campaign. Fake security alerts steal passwords and real-time 2FA codes from Polish users.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 10 July 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
A fake login alert, a threat to suspend the account and a page that closely resembles Gmail: the pattern is familiar, but the campaign described by CERT Polska on 12 June 2026 stands out for its intensity, target selection and ability to steal a second authentication factor.
The UNC1151/Ghostwriter cluster has targeted Polish citizens for years. Since March 2026, it has run an intensive campaign against Gmail, and CERT Polska observed new phishing domains almost every day.
This is not a breach of Google or a technical bypass of Gmail security. Attackers imitate the login flow and capture information entered by the victim in real time.
Who is targeted
CERT Polska says the group targets people involved in politics and public life, journalists, researchers, government employees, uniformed services, translators and court experts. Family and contacts may also be approached because their accounts contain useful information or relationships.
Attackers sometimes guess addresses based on first and last names, so a malicious message can reach an unintended recipient. Receiving one does not prove that the person was a individually selected intelligence target, but the email is still a genuine account-theft attempt.
How the phishing works
- The message imitates a Gmail alert. It claims suspicious activity, a new-device login, a terms violation or an urgent verification deadline.
- The email looks credible. Polish language is generally good. Messages often come from newly created Gmail accounts or already compromised mailboxes, with a manipulated display name.
- The link opens a fake Google login. The page collects email address and password. The browser’s actual domain remains the most reliable visible clue.
- The attacker logs in immediately. If Google asks for a second factor, the fake page requests an SMS or authenticator code and the operator uses it before expiry.
- Pressure is repeated. CERT Polska observed several messages sent to the same person over two days, with a shrinking “time before suspension”.
This is real-time phishing. It does not break 2FA; it persuades the user to relay a valid code. A second factor still protects against a password-only leak, but not every social-engineering scenario.
Fast-changing infrastructure
UNC1151 uses purpose-registered domains, including .icu, .digital and .top, hosting subdomains such as netlify.app, and compromised Polish websites. On a hijacked site the attacker may hide the phishing panel under an additional path while leaving the homepage unchanged.
Rapid domain changes reduce the value of static blocklists. Email filtering remains useful, but fresh infrastructure may not yet have a reputation score.
How to recognise a fake alert
- Check the complete domain before entering credentials.
- Inspect the real sender address, not only the display name.
- Open Google account security settings independently and look for the event there.
- Treat immediate suspension threats as manipulation.
- Never reauthenticate through an unexpected email link.
The safest approach is to open account settings through a saved bookmark or manually typed official address. If the warning is real, it should also appear in the account without using the message link.
Reducing account-takeover risk
Use phishing-resistant authentication. SMS and authenticator codes are better than a password alone, but can be relayed. Passkeys and FIDO hardware keys bind authentication to the legitimate domain and are much harder to phish.
High-risk staff need an easy path for checking suspicious messages, including private accounts used for professional contacts. Monitor new devices, recovery changes, forwarding rules, hidden filters and application passwords—not only login events.
What to do after entering credentials
From a trusted device:
- change the Google password and end other sessions;
- remove unknown devices and connected applications;
- review MFA methods, recovery details and app passwords;
- inspect mail forwarding, filters and deleted messages;
- secure other accounts recovered through this mailbox;
- notify administrators and contacts who may receive messages from the account;
- report the phishing page or message to CERT Polska.
Changing the password alone is insufficient if the attacker added their own recovery method, session or forwarding rule.
The campaign shows that Polish-language phishing can be well written and operationally adaptive. Defenders should evaluate domain and context—not the quality of the logo—and move valuable accounts to phishing-resistant authentication.
Sources: CERT Polska campaign analysis, Polish version, CERT-EU Cyber Brief.


