UNC1151 has moved from local Polish mail providers to Gmail, which gives the campaign a much larger and more portable target surface. The key break is not the inbox itself. It is the trusted account-reset and contact graph that a stolen mailbox opens up, plus linked accounts that can be taken over next.
CERT Polska says the group has been running high-intensity Gmail phishing since March 2026, with new phishing domains appearing almost daily. The messages pose as Gmail support, push victims to a fake login page, and capture both passwords and 2FA credentials, which lets attackers sign in and then mine contacts, documents, and connected accounts such as social media.
For security and identity teams, the risk now sits in downstream abuse after the mailbox is lost. A single compromise can expand across personal, professional, and linked accounts, and the move to Gmail broadens the campaign beyond Poland's domestic providers.