Lead
Key takeaway: phishing does not always originate from a fake domain or anonymous sender. Once an attacker compromises a legitimate business account, they can exploit recipient trust, message history, and the organization’s authority to conduct further fraud.
The Cyber Defence Component Command of the Polish Armed Forces, known as DKWOC, reported unauthorized access to an unclassified official email mailbox belonging to one member of the Polish Armed Forces. According to the public statement, the incident resulted from targeted social engineering against an individual user.
After gaining access, the adversary used the compromised mailbox to launch phishing attacks against organizations in Poland and abroad. DKWOC stated that no classified information was processed in the affected mailbox and that relevant cybersecurity teams at the targeted entities were informed.
Knowledge status: 18 July 2026
Primary source: Public statement by the Polish Cyber Defence Forces.
Scope: Publicly available facts and practical lessons for B2B organizations.
What has been confirmed
The public statement confirms the following:
- An official, unclassified business mailbox belonging to one user was accessed without authorization
- The initial compromise resulted from targeted social engineering
- No classified information was processed in the affected mailbox
- The compromised account was used to send phishing messages to organizations in Poland and abroad
- DKWOC conducted technical analysis of secured digital evidence and actions to limit the impact
- Relevant cybersecurity teams at the targeted organizations were notified
What has not been confirmed
A responsible incident analysis must also define the limits of available knowledge. The public statement does not disclose:
- The attacker’s identity or affiliation
- The specific technique used to compromise the account
- Whether the attack involved a fake login page, malicious attachment, session theft, credential theft, or another method
- The number of organizations that received phishing messages
- The success rate of the phishing campaign
- The impact on recipient organizations
- Any compromise of the wider military email or network infrastructure
There is therefore no basis for attributing the incident to a specific APT group, state actor, or criminal organization. There is also no basis for claiming that classified information was leaked; the public statement explicitly says that such information was not processed in the affected mailbox.
Why a compromised mailbox matters
A compromised email account can be more dangerous than ordinary phishing sent from a suspicious external domain. The message may come from a legitimate organizational address that the recipient already knows and trusts.
An attacker may exploit:
- A legitimate sender domain
- Existing email threads and message history
- Contact lists and established business relationships
- Context around projects, invoices, meetings, or deliveries
- Valid signatures, branding, and message formatting
- Trust created by B2B, administrative, or partner relationships
For the recipient, the message may appear credible even if the sender organization has correctly configured SPF, DKIM, and DMARC. These controls are essential for reducing domain spoofing, but they cannot stop a message sent from a real mailbox that has already been compromised.
This is a core feature of business email compromise (BEC) risk: evaluating the sender domain alone is not enough. Organizations must also evaluate context, requested actions, and unusual sender behavior.
The attack chain
The public information supports the following high-level incident model without speculating about the initial access technique:
- Reconnaissance and targeting — a single user is selected for targeted social engineering.
- Account compromise — the attacker obtains the ability to use the victim’s official mailbox.
- Trust abuse — the attacker uses a legitimate account and domain to make messages appear credible.
- Secondary phishing — phishing messages are sent to other organizations in Poland and abroad.
- Containment and response — the account owner analyzes the incident, secures digital evidence, and alerts potentially affected entities.
This model matters to every B2B organization. One compromised user can become the starting point for fraud against customers, suppliers, partners, finance teams, or operational staff.
Lessons for B2B organizations
- Protect identity, not only mailboxes.
Email is now an identity service as much as a communication service. A compromised account may expose not only messages, but also SaaS applications, calendars, contacts, documents, and approval workflows.
Multi-factor authentication should be mandatory for higher-risk accounts, including executives, finance, sales, administration, IT, and employees who communicate with customers. Where possible, use phishing-resistant MFA methods such as FIDO2/WebAuthn security keys or passkeys. - Monitor post-login behavior.
MFA does not replace monitoring. Organizations need to detect not only failed login attempts, but also suspicious actions after an account has been accessed. Pay particular attention to:- Logins from unusual locations, devices, or networks
- Enrollment of new MFA methods
- Creation of mailbox forwarding rules
- Changes to mailbox delegation
- OAuth application consent or registration
- Unusual outbound email volume or sending patterns
- Deletion of messages, alerts, or communication traces
- Export of contacts, files, or mailbox data
- Secure the domain, but do not assume full protection.
SPF, DKIM, and DMARC remain core email-security controls. They reduce domain impersonation, help recipients assess message authenticity, and improve brand resilience against conventional phishing.
However, they should not be treated as complete protection. If a message is sent from a genuine compromised mailbox, it may pass domain-authentication checks. Additional layers are required: identity controls, behavior monitoring, business procedures, and user awareness. - Verify outside the email channel.
Any request involving payment, a change of bank details, supplier-data changes, data sharing, access reset, or urgent action should have an independent verification channel. A practical rule is:
Verification should take place through a known phone number, a previously established communication channel, a customer-service system, or an approved internal workflow. Do not rely on a phone number or link provided in the suspicious message.The more urgent, unusual, or costly an email request is, the less you should rely on email alone.
- Prepare an account-compromise response procedure.
Organizations should not improvise during an incident. A response plan should include at least:- Immediate account lockdown or credential reset
- Revocation of active sessions and access tokens
- Review of mailbox rules, delegation, forwarding, and OAuth applications
- Analysis of login and account activity
- Identification of recipients contacted after the compromise
- Warning customers and partners if the account was used for phishing
- Preservation of logs and technical evidence
- Incident reporting in line with applicable requirements and procedures
What to do with a suspicious message
If a message comes from a known contact but includes an unusual request, link, attachment, or time pressure:
- Do not click the link or open the attachment
- Do not reply to the message to ask whether it is genuine
- Verify the request using an independent, known communication channel
- Report the message to IT, security, or the email provider
- Preserve the message and its email headers as evidence
- If phishing is suspected in Poland, report it to CERT Polska through incydent.cert.pl or by email at cert@cert.pl
For suspicious SMS messages in Poland, forward the complete message to CERT Polska at 8080. Official guidance recommends avoiding links until a message’s authenticity is confirmed and reporting suspicious messages and websites.
Email security checklist
This list does not replace a full assessment, but it provides a fast baseline for organizational maturity:
- MFA is mandatory for all email accounts
- Privileged accounts use phishing-resistant MFA methods
- Legacy authentication protocols are disabled or tightly restricted
- Logins, new devices, and unusual locations are monitored
- Mailbox forwarding rules and delegations are monitored
- OAuth applications with mail access are controlled
- SPF, DKIM, and DMARC are configured and reviewed periodically
- Payment-detail changes require out-of-band confirmation
- Users know how to report suspicious messages
- A documented account-compromise response procedure exists
- The business can quickly notify customers and partners about phishing sent from a compromised account
How CHORS.NET can help
CHORS.NET helps manufacturing, technology, and service organizations understand their digital exposure and identify risk areas before they become business incidents.
In the context of email and identity security, our work can include:
- Public exposure of internet-facing domains and services
- Baseline email-domain security configuration
- Risks associated with publicly available email addresses and user roles
- Exposure to spear-phishing and brand impersonation
- Externally visible signals that can support social-engineering attacks
- Prioritized actions to reduce risk in a B2B environment
A question for management and IT: would your organization detect a compromised mailbox before it is used to phish customers, suppliers, or employees?
Contact CHORS.NET to discuss digital-exposure assessment and cybersecurity priorities.
Frequently asked questions
Do SPF, DKIM, and DMARC prevent phishing from a compromised account?
Not completely. SPF, DKIM, and DMARC help reduce domain impersonation, but they cannot stop messages sent from a legitimate mailbox that an attacker has compromised. Organizations also need MFA, account-behavior monitoring, and verification procedures for critical requests.
Can one compromised email account put the whole business at risk?
It can significantly increase risk. An attacker may use one mailbox to phish company contacts, exploit communication history, collect information about business processes, and attempt access to other systems or users.
How can you identify phishing sent from a genuine email address?
Do not judge a message only by the sender domain. Warning signs include unusual requests, urgency, payment-detail changes, login links, unexpected attachments, or instructions to bypass normal procedures. Confirm the request through an independent communication channel.
What should a company do when an email account is compromised?
Immediately secure or disable the account, revoke active sessions, reset credentials, review MFA methods, forwarding rules, and applications with mailbox access. Then establish the scope of activity, preserve evidence, and warn parties who may have received attacker-sent messages.
Sources
- Polish Cyber Defence Forces / DKWOC — public statement on X regarding unauthorized access to an official unclassified email account and its use for phishing, 17 July 2026.
- CERT Polska — incident reporting form (incydent.cert.pl)
- CHORS.NET — contact