Threat Intelligence

FBI and Allies Warn of China-Linked Email Theft Campaign With a Portal for Third-Party Access

The Hacker News · 9 Oct 2026
Key Takeaway Protect Microsoft 365 and Exchange accounts with strong, unique passwords and multi-factor authentication, and watch for repeated failed logins that could signal password guessing.

The FBI and agencies in six other countries said on October 8 that hackers tied to Chinese cybersecurity company Integrity Technology Group stole email from government bodies, law enforcement agencies, healthcare systems and religious institutions in Southeast Asia. The same group also targeted US government services, critical manufacturing, healthcare, IT, education and religious organisations, along with targets in Africa and North America. The company has been sanctioned by the US and the UK.

According to the joint advisory, the hackers scanned websites for flaws using a tool with more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes with tools built to collect mail. They have been breaking into networks since at least mid-January 2021. The advisory also says they run a web application that "provides third-party access to stolen email content", though it does not name those third parties. It gives no dates for any theft and does not say how many organisations were breached.

The advisory builds on the FBI's September 2024 disruption of a botnet, a network of hijacked devices, which the US Justice Department said the company controlled. That network held more than 200,000 routers, cameras and other consumer devices. The new advisory instead covers how the hackers get in and what they take, drawing on evidence from several investigations. The US sanctioned the company in January 2025 and the UK followed in December 2025.

China Email security Microsoft 365 FBI advisory Password guessing

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.