FBI: China-Linked Hackers Ran a Portal Giving Third Parties Access to Stolen Emails
What happened
The FBI, alongside agencies from six other countries, said on October 8 that hackers tied to a Chinese cybersecurity company, Integrity Technology Group, stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia. According to the joint advisory, the operators scanned websites for vulnerabilities using an in-house tool, and ran a portal that gave third parties access to the stolen email data. Integrity Technology Group has previously been sanctioned by both the U.S. and the UK.
Why it matters for defenders
This is a state-linked, vendor-backed access-selling operation rather than an isolated intrusion set — the targeting spans multiple sensitive sectors (government, law enforcement, healthcare, religious organizations) in a specific region, and the existence of a portal suggests stolen mailbox access was distributed or monetized beyond the original intrusion actor. Organizations in the named sectors and region should treat this as a signal that mass web-facing vulnerability scanning followed by email-system compromise is an active, ongoing technique associated with this actor, not a one-off event.
What defenders should watch for or do now
- Review internet-facing web applications and email infrastructure (webmail portals, OWA/Exchange front-ends, admin panels) for unpatched vulnerabilities, since the advisory describes vulnerability scanning as the initial access method.
- Hunt for anomalous authentication to mailbox accounts: logins from unexpected geographies/ASNs, impossible-travel patterns, and bulk mailbox exports or delegated-access/forwarding rule changes.
- Audit mail-flow and audit logs for unusual API or IMAP/EWS access patterns that could indicate bulk email exfiltration rather than normal user activity.
- Tighten external exposure of admin and mail-management interfaces, and ensure MFA is enforced on all mailbox and portal accounts.
- Organizations in government, law enforcement, healthcare, or religious-sector roles in Southeast Asia should treat this advisory as a priority read and cross-check any indicators the agencies publish against their own logs.
Developing story
No CVE or specific vulnerability has been disclosed in this reporting, and the full technical advisory (scanning tool details, indicators of compromise) has not been summarized here — this write-up reflects only what has been reported so far and will be updated as more detail emerges. Read the original report at The Hacker News.