GhostWriter is no longer just chasing the official’s work inbox. It is widening into personal Gmail and family-linked accounts, which breaks the usual assumption that protecting the corporate mailbox contains the risk. Once the attacker gets into a personal account, the social graph becomes the entry point to the target’s circle.
CERT Polska says the group has shifted from Polish work accounts and local email providers to Gmail since March, with new phishing domains appearing almost daily. The phishing steals passwords and two-factor codes, then the attackers use inboxes, contact lists, sensitive documents, and linked accounts to find new targets or take over social media profiles. The current wave covers public figures, government staff, researchers, journalists, law enforcement, and their relatives and contacts.
That makes personal email a persistence path into official networks, not just a side target. A compromised relative’s account can expose the relationships and recovery channels that lead back to the real target.