Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Seven governments pin a stolen-email portal on sanctioned Integrity Technology Group

The FBI and six other governments said on October 8 that hackers tied to Integrity Technology Group run a portal giving third parties access to stolen email. The firm, sanctioned by the US and UK, denies the accusations.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Seven governments pin a stolen-email portal on sanctioned Integrity Technology Group
Generated illustration

What happened

  • The hackers hunt flaws with open-source scanners Nmap, masscan and WPScan, focusing their probes on ports 21, 22, 53, 80, 443 and 1080.
  • They guess passwords for Microsoft 365 and Exchange accounts, then copy entire mailboxes with tools built to collect mail.
  • A scanner called MicroScan, in use since at least 2017, carries more than 1,300 penetration-testing scripts aimed at OpenSSL, Oracle WebLogic Server, WordPress, Jenkins and Apache Struts.
  • The advisory lists eight flaws it says the crews exploited successfully, taken from those penetration-testing scripts.
  • Named targets span US government, critical manufacturing, healthcare, IT, law enforcement, education and religious groups, plus organizations in Southeast Asia, Africa and North America.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The portal's customers go unnamed. Victims whose mail was taken have no way to learn where their correspondence ends up or who else can read it.
  • capability Because the advisory hands over tool names, fixed scan ports and specific exploited flaws, defenders can write detections from these now.
  • contradiction The NCSC's release calls the hackers 'uniquely' reliant on AI tools. That claim appears only in the release, not in the advisory text.
  • constraint The advisory gives no theft dates or number of victims. Defenders are left to work out for themselves how large the loss is and whether their own mail is gone.

The agencies describe Integrity Technology Group as "a China-based for-profit company with links to the Chinese government" whose employees build or obtain cyber tools "for use and sale," host infrastructure and break into networks [11]. The advisory uses one label, "the threat actors," for the company and the hackers it enables, and does not say which of them ran a given break-in [12]. It rests on evidence the FBI recovered and observed across several investigations into the company [23].

The crews favor commodity tooling. "The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets," the agencies wrote [17]. Their methods are "consistent with" activity other firms track as Flax Typhoon, Ethereal Panda and RedJuliett, though the advisory warns those names may not map one-to-one to US government tracking [14]. Flax Typhoon is Microsoft's name for a China-based group it described in 2023 as targeting organizations in Taiwan [21].

Christopher Wray, then the FBI director, said in 2024 that the company's "chairman has publicly admitted that for years his company has collected intelligence and performed reconnaissance for Chinese government security agencies" [13]. The US Treasury sanctioned the firm in January 2025 for its role in computer break-ins against US victims, and the UK followed in December 2025 [2][3]. Integrity Technology Group rejected the US accusations that January, telling the Shanghai Stock Exchange the move had no factual basis, the Associated Press reported [15]. A Chinese Foreign Ministry spokesperson said China firmly opposed the action, according to the same report [22].

The US has acted against the company before. In September 2024 the FBI disrupted a botnet the Justice Department said Integrity Technology Group controlled, a network of more than 200,000 routers, cameras and other consumer devices that Lumen researchers named Raptor Train [9]. That operation dealt with hijacked infrastructure. The new advisory covers how the crews get into networks and what they take, activity it dates to at least mid-January 2021 [10][5].

What to watch

  • Whether follow-up actions or indictments identify the third parties using the stolen-email portal, or any buyers of the company's tooling.
  • Whether more governments join the advisory or reconcile the Flax Typhoon, Ethereal Panda and RedJuliett names with their own tracking.
  • Any new US or UK sanctions action, and any response from Integrity Technology Group beyond its January 2025 denial.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    The FBI and agencies in 6 other countries said on October 8 that hackers tied to Integrity Technology Group stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia.

    ReportedSupportedView cited source
  2. [2]

    The U.S. Treasury sanctioned Integrity Technology Group in January 2025 for its role in several computer break-ins against U.S. victims.

    ReportedSupportedView cited source
  3. [3]

    The UK sanctioned Integrity Technology Group in December 2025.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 8, 2026

    FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories