China-linked Integrity Tech portal sold stolen emails

Hackers tied to Chinese cybersecurity firm Integrity Technology Group operated an online portal that gave third parties access to stolen emails from government, law enforcement, healthcare, and religious organizations across Southeast Asia, according to a joint advisory issued by the FBI and agencies in six other countries on October 8[2][12].

Integrity Technology Group, a Beijing-based contractor, has already been sanctioned by the United States and United Kingdom for its role in a series of computer intrusions and botnet operations that targeted public sector and critical infrastructure networks[1][5][7]. The U.S. government has linked the company to the prolific hacking group known as “Flax Typhoon” and described Integrity Tech as having ties to China’s Ministry of State Security, with personnel developing and deploying offensive cyber tools on behalf of state-directed operations[5][11].

The newly described campaign goes beyond network compromise to industrialized exploitation of stolen data, with authorities saying the attackers maintained a web application that “provides third-party access to stolen email content,” effectively turning victims’ mailboxes into a searchable data store for unknown customers or partners[2]. The advisory notes that compromised organizations spanned sensitive sectors, including government ministries, police agencies, hospital systems, and religious institutions, raising concerns that operational plans, personal information, and internal communications may have been exposed and monetized over an extended period[2][12].

Sanctions records show that Integrity Tech previously controlled and managed a covert botnet of more than 260,000 compromised devices worldwide, supplying access to this infrastructure to enable unauthorized intrusion into public-sector IT systems and data in the U.K. and elsewhere[7][10][13]. In March 2026, the European Union also imposed cyber sanctions on Integrity Technology Group, citing its role in large-scale attacks that enabled hacks of tens of thousands of devices across multiple member states and imposing asset freezes and travel bans on associated entities and individuals[3][6][14].

U.S. authorities have moved to disrupt parts of Integrity Tech’s tooling ecosystem, seizing domains associated with the Microscan vulnerability scanning platform and the FishHub spearphishing tool, both linked to Flax Typhoon and developed or operated by Integrity Technology Group[8][11]. These tools were allegedly used to identify weaknesses in public-facing systems and deliver targeted phishing campaigns, which in turn facilitated access to email accounts and internal networks that fed data into the stolen-email portal[8].

While the advisory does not publicly specify individual vulnerabilities or CVE identifiers exploited in the Southeast Asia campaign, the operation underscores ongoing risk from widely used scanning and phishing toolchains and long-lived email compromises that may persist undetected. Defenders in government, healthcare, and faith-based sectors should prioritize hardening webmail and remote-access systems, enforcing multi-factor authentication, closely reviewing anomalous login patterns, and coordinating with national cyber agencies for updated indicators of compromise and guidance tailored to Integrity Tech and Flax Typhoon-linked activity.

References

  1. Treasury Sanctions Technology Company for Support to …
  2. FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
  3. Integrity Technology Group | EU sanctions tracker
  4. Sanctioning PRC Cyber Company Involved in Malicious …
  5. EU sanctions Chinese and Iranian companies for …
  6. Sanctions Update: Cyber
  7. DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
  8. [PDF] Financial Sanctions Notice
  9. US sanctions China’s Integrity Technology over alleged …
  10. Hackers ligados à China davam acesso a e-mails roubados, segundo FBI
  11. Sanctions Notice – Cyber — GFSC
  12. The EU sanctions several private cyber offensive ecosystem actors

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply