Security1 publisherNot yet confirmed elsewhere2 min readPublished
Seven governments pin a stolen-email portal on sanctioned Integrity Technology Group
The FBI and six other governments said on October 8 that hackers tied to Integrity Technology Group run a portal giving third parties access to stolen email. The firm, sanctioned by the US and UK, denies the accusations.
The Watch · Security desk

What happened
- The hackers hunt flaws with open-source scanners Nmap, masscan and WPScan, focusing their probes on ports 21, 22, 53, 80, 443 and 1080.
- They guess passwords for Microsoft 365 and Exchange accounts, then copy entire mailboxes with tools built to collect mail.
- A scanner called MicroScan, in use since at least 2017, carries more than 1,300 penetration-testing scripts aimed at OpenSSL, Oracle WebLogic Server, WordPress, Jenkins and Apache Struts.
- The advisory lists eight flaws it says the crews exploited successfully, taken from those penetration-testing scripts.
- Named targets span US government, critical manufacturing, healthcare, IT, law enforcement, education and religious groups, plus organizations in Southeast Asia, Africa and North America.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The portal's customers go unnamed. Victims whose mail was taken have no way to learn where their correspondence ends up or who else can read it.
- capability Because the advisory hands over tool names, fixed scan ports and specific exploited flaws, defenders can write detections from these now.
- contradiction The NCSC's release calls the hackers 'uniquely' reliant on AI tools. That claim appears only in the release, not in the advisory text.
- constraint The advisory gives no theft dates or number of victims. Defenders are left to work out for themselves how large the loss is and whether their own mail is gone.
The agencies describe Integrity Technology Group as "a China-based for-profit company with links to the Chinese government" whose employees build or obtain cyber tools "for use and sale," host infrastructure and break into networks [11]. The advisory uses one label, "the threat actors," for the company and the hackers it enables, and does not say which of them ran a given break-in [12]. It rests on evidence the FBI recovered and observed across several investigations into the company [23].
The crews favor commodity tooling. "The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets," the agencies wrote [17]. Their methods are "consistent with" activity other firms track as Flax Typhoon, Ethereal Panda and RedJuliett, though the advisory warns those names may not map one-to-one to US government tracking [14]. Flax Typhoon is Microsoft's name for a China-based group it described in 2023 as targeting organizations in Taiwan [21].
Christopher Wray, then the FBI director, said in 2024 that the company's "chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies" [13]. The US Treasury sanctioned the firm in January 2025 for its role in computer break-ins against US victims, and the UK followed in December 2025 [2][3]. Integrity Technology Group rejected the US accusations that January, telling the Shanghai Stock Exchange the move had no factual basis, the Associated Press reported [15]. A Chinese Foreign Ministry spokesperson said China firmly opposed the action, according to the same report [22].
The US has acted against the company before. In September 2024 the FBI disrupted a botnet the Justice Department said Integrity Technology Group controlled, a network of more than 200,000 routers, cameras and other consumer devices that Lumen researchers named Raptor Train [9]. That operation dealt with hijacked infrastructure. The new advisory covers how the crews get into networks and what they take, activity it dates to at least mid-January 2021 [10][5].
What to watch
- Whether follow-up actions or indictments identify the third parties using the stolen-email portal, or any buyers of the company's tooling.
- Whether more governments join the advisory or reconcile the Flax Typhoon, Ethereal Panda and RedJuliett names with their own tracking.
- Any new US or UK sanctions action, and any response from Integrity Technology Group beyond its January 2025 denial.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
The FBI and agencies in 6 other countries said on October 8 that hackers tied to Integrity Technology Group stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia.
- [2]
The U.S. Treasury sanctioned Integrity Technology Group in January 2025 for its role in several computer break-ins against U.S. victims.
- [4]
The hackers guessed passwords for Microsoft 365 and Exchange accounts and copied mailboxes using tools designed to collect mail.
- [5]
The hackers have been breaking into networks since at least mid-January 2021, according to the joint advisory.
- [6]
The advisory describes the hacking in the present tense but provides no date for any theft and does not specify how many organizations were breached.
- [7]
The same hackers targeted U.S. government services, critical manufacturing, healthcare, and IT organizations, along with U.S. law enforcement, education, and religious groups; organizations in Southeast Asia, Africa, and North America were also targeted.
- [8]
The hackers run a web application that "provides third-party access to stolen email content," the advisory said, and it does not identify those third parties.
- [9]
In September 2024 the FBI disrupted a botnet the Justice Department said Integrity Technology Group controlled; it held more than 200,000 routers, cameras, and other consumer devices, and Lumen researchers named it Raptor Train.
- [10]
The new advisory covers how the hackers get into networks and what they take.
- [11]
The agencies describe Integrity Technology Group as "a China-based for-profit company with links to the Chinese government" whose employees build or get cyber tools "for use and sale," host infrastructure, and break into networks.
- [12]
The advisory uses a single label, "the threat actors," for the company and the hackers it enables, and does not say which of them carried out each break-in.
- [13]
Christopher Wray, then the FBI director, said in 2024 that the company's "chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies."
ReportedSupportedSource: Christopher Wray, then FBI director, in 2024, per the advisory accountView cited source - [14]
The hackers' methods are "consistent with" activity that security companies track as Flax Typhoon, Ethereal Panda, and RedJuliett, among others, the advisory said, and those names may not match the U.S. government's own tracking one-to-one.
- [15]
Integrity Technology Group rejected the U.S. accusations in January 2025, telling the Shanghai Stock Exchange the U.S. move had no factual basis, the Associated Press reported.
ReportedSupportedSource: Integrity Technology Group, to the Shanghai Stock Exchange, per the Associated PressView cited source - [16]
The hackers look for flaws with open-source scanners such as Nmap, masscan, and WPScan, and their scans focus on ports 21, 22, 53, 80, 443, and 1080.
- [17]
"The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets," the agencies said.
- [18]
The hackers have used a scanner called MicroScan since as early as 2017, a Python web application containing more than 1,300 penetration testing scripts, used against services including OpenSSL, Oracle WebLogic Server, Rejetto HFS, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts.
- [19]
The advisory lists 8 known flaws that it says were successfully exploited, found in the hackers' penetration testing scripts.
- [20]
The UK's National Cyber Security Centre said in its news release that the hackers are "uniquely using AI tools, such as automated scanning," while the advisory itself does not mention AI.
- [21]
Flax Typhoon is Microsoft's name for a China-based group that it described in 2023 as targeting organizations in Taiwan.
- [22]
A Chinese Foreign Ministry spokesperson, asked about the sanctions, said China firmly opposed the U.S. action, according to the Associated Press.
ReportedSupportedSource: Chinese Foreign Ministry spokesperson, per the Associated PressView cited source - [23]
The advisory is based on evidence the FBI recovered and observed during several investigations related to the company.
- [24]
Seven governments produced the advisory: the FBI and agencies in six other countries.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comFBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Email Account CompromiseFollow
- State-Linked Cyber EspionageFollow
- Known Exploited Vulnerabilities catalogFollow
- Cyber sanctionsFollow
Entities
- Integrity Technology GroupFollow
- Federal Bureau of InvestigationFollow
- National Cyber Security CentreFollow
- CISAFollow
- Known Exploited Vulnerabilities CatalogFollow
- Flax TyphoonFollow
- Raptor TrainFollow
- MicroScanFollow
- Christopher WrayFollow
- Lumen TechnologiesFollow
- MicrosoftFollow