FBI and allies say China-linked Integrity Tech ran portal selling access to stolen emails
A joint advisory from agencies in eight countries details how Integrity Technology Group-linked hackers stole email and offered third parties access through a web portal.
At a glance
- FBI, CISA, NSA and partners in seven other countries published joint advisory AA26-281A on October 8, 2026.
- Actors linked to Integrity Technology Group stole email from government, law enforcement, healthcare and religious organizations, mainly in Southeast Asia.
- A web application let third parties read specific stolen mailboxes, according to The Hacker News.
- Eight exploited flaws are listed; five old bugs, including Apache Struts and ISC BIND, were newly added to CISA's KEV catalog.
The FBI, CISA, the NSA and cybersecurity agencies from the United Kingdom, Australia, Canada, Japan, New Zealand and Spain published a joint advisory on October 8, 2026, warning that hackers tied to the Chinese company Integrity Technology Group have been breaking into networks since at least mid-January 2021 to steal sensitive data. According to The Hacker News, the attackers stole email from government, law enforcement, healthcare and religious organizations, mainly in Southeast Asia, and operate a web application that gives third parties access to that stolen mail.
What happened
The advisory, tracked as AA26-281A, describes Integrity Tech as a China-based for-profit company with links to the Chinese government that builds or acquires cyber tools, hosts infrastructure and compromises networks. CISA says its activity overlaps with groups publicly tracked as Flax Typhoon, Ethereal Panda and Red Juliett, although those actors may also operate independently.
Targets listed in the advisory include US government services, critical manufacturing, healthcare and information technology, as well as law enforcement, education and religious groups in the US, Southeast Asia and Africa. The Hacker News notes that the advisory does not say how many organizations were breached or identify the third parties using the email portal, which it says can display a specific account's mail through URL parameters. The US Treasury sanctioned Integrity Tech in January 2025; the company rejected the accusations at the time, the publication reported.
Technical details
According to CISA, the actors combine automated scanning with hands-on intrusions. A scanning toolset in use since as early as 2017 probes services such as FTP, SSH, DNS and web servers. The advisory lists eight successfully exploited vulnerabilities, including CVE-2019-11510 (Pulse Connect Secure), CVE-2021-22205 (GitLab) and CVE-2014-6278 (GNU Bash). Five of them, CVE-2015-3306 (ProFTPD), CVE-2015-5477 (ISC BIND), CVE-2016-3081 (Apache Struts), CVE-2021-3199 (ONLYOFFICE Document Server) and CVE-2023-22894 (Strapi), were added to CISA's Known Exploited Vulnerabilities catalog the same day.
Other techniques described include cross-site scripting payloads that display fake login fields, password spraying with the open-source EBurst tool against Exchange and Microsoft 365, DCSync credential theft through a tool named DC.exe, and SoftEther VPN clients disguised as conhost.exe or dllhost.exe for persistence. Email was collected with a PHP script called Curlc4 via Exchange Web Services and with a tool named office-cli for Microsoft 365. The Hacker News reports that the indicator list runs to 39 pages, with some entries dating back to 2016, and that the UK's NCSC said the group uses AI tools for scanning, a point not made in the advisory itself.
What to do
The agencies urge organizations to patch the eight listed flaws and replace end-of-life products, disable unused services and ports, require multifactor authentication for webmail and VPN access, and sanitize web application input against XSS. Defenders should monitor for unexpected Active Directory replication, review cloud applications with permission to read mail and files, and check web logs for exploitation attempts. CISA advises vetting older indicators before blocking them, and isolating affected hosts and scoping the intrusion if compromise is suspected.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



