Security

China-linked hackers built a web portal for browsing stolen email

(today) · 3 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • A joint advisory on 8 October links the activity to Integrity Technology Group, sanctioned by the US and UK
  • The hackers ran a web app giving third parties access to stolen email, and have been active since at least January 2021
  • Initial access leaned on old bugs, password spraying against Microsoft 365 and Exchange, and a fake login page
  • The advisory lists eight CVEs and defences including MFA, cloud app audits and DCSync monitoring

The FBI and agencies in six other countries published a joint advisory on 8 October 2026 describing something unusually blunt: a web application that gives third parties access to stolen email. The advisory ties the activity to Integrity Technology Group, a China-based company the US sanctioned in January 2025 and the UK sanctioned in December 2025.

A portal, not just a breach

Most breach stories end with data dumped somewhere. This one describes a product. Users can reportedly open a specific account's mail by adding arguments to a URL, and some of the stolen data was restricted to IP addresses in Xiamen, China. The advisory does not say who the third parties are, or how many organisations were breached. It says the hackers have been inside networks since at least mid-January 2021.

Victims named include government bodies, law enforcement, healthcare systems and religious groups in Southeast Asia, plus US government services, critical manufacturing, education and IT firms, with targets in Africa and North America too. The methods are consistent with groups tracked as Flax Typhoon, Ethereal Panda and RedJuliett. In September 2024 the FBI disrupted the Raptor Train botnet, which the Justice Department said the company controlled. The company has rejected the US accusations.

Boring tools, big results

None of this relies on exotic malware. The advisory lists open-source scanners, a Python toolkit with more than 1,300 scripts, password spraying with the EBurst tool against Microsoft 365 and Exchange, and a fake login page that harvested credentials. For persistence the hackers used SoftEther VPN with installers renamed to look like Windows files. To pull mail they used Exchange Web Services and a tool that reads Microsoft 365 mailboxes with stored app credentials.

Eight CVEs are named, and several date back a decade, including a 2014 Bash bug and a 2019 Pulse Connect Secure flaw. Old, unpatched kit is still the cheapest way in.

What to do

The advisory's defences are plain, which is the point:

  • Turn on multifactor authentication for webmail, VPNs and critical accounts. A hardware key such as the YubiKey 5 NFC beats codes that can be phished.
  • Audit your cloud accounts for connected apps that can read mail or files, and remove what you do not recognise.
  • Watch for unexpected Active Directory replication, a sign of DCSync credential theft.
  • Retire products that no longer get security updates.

Our passkeys versus security keys guide covers which accounts deserve a physical key first.

Some links in this article may be affiliate links. We only recommend products we genuinely think are worth your time.

More from Future Technology