A joint advisory from the FBI and partner agencies from six other nations has exposed new details about a hacking campaign conducted by actors associated with the sanctioned Chinese cybersecurity company, Integrity Technology Group. The advisory, released on October 8, 2026, reveals that the threat actors not only stole vast amounts of email data but also operated a web application that provided third-party access to the stolen content. The campaign, active since at least mid-January 2021, targeted a broad spectrum of organizations across North America, Southeast Asia, and Africa. Victims included government agencies, law enforcement, healthcare systems, and critical manufacturing. This operation highlights a potential 'hacker-for-hire' model where stolen data is productized and made available to other entities.
The campaign is attributed to actors linked to Integrity Technology Group, a company previously sanctioned by the U.S. and U.K. for its malicious cyber activities. The group's primary objective was the large-scale theft of email communications from targeted organizations. The scope of targeting was extensive, encompassing government services, critical manufacturing, healthcare, IT, law enforcement, education, and religious institutions in the United States alone.
A key and highly concerning finding from the advisory is the existence of a web portal operated by the hackers. This portal served as a repository for the stolen email content and provided access to unidentified third parties. This suggests a sophisticated operation that goes beyond simple intelligence gathering, potentially offering a 'data-access-as-a-service' to other actors, which could include other intelligence services or commercial entities.
The FBI's insights are based on evidence recovered during multiple investigations, including the disruption of the 'Raptor Train' botnet in September 2024, which was also controlled by Integrity Technology Group.
The threat actors employed a multi-pronged approach to gain access and exfiltrate data from target networks.
T1190 - Exploit Public-Facing Application: The use of a large-scale scanning tool to find and exploit web vulnerabilities for initial access.T1110.001 - Password Guessing: The actors attempted to compromise accounts by guessing passwords.T1110.003 - Password Spraying: A likely technique used to target a large number of accounts with common passwords.T1114.002 - Remote Email Collection: The primary goal and activity was the exfiltration of data from Exchange and Microsoft 365 mailboxes.T1020 - Automated Exfiltration: The use of specialized tools to copy entire mailboxes suggests an automated exfiltration process.The impact of this campaign is significant due to its scale, the sensitivity of the targeted sectors, and the novel data-sharing model. For the breached organizations, the theft of email communications can expose sensitive government information, trade secrets, intellectual property, and personal data. The targeting of law enforcement and healthcare has serious implications for public safety and privacy.
The existence of a portal for third-party access represents a major escalation. It indicates that the stolen data is not just being used by the primary threat actor but is being disseminated, multiplying the potential for harm. This could enable parallel intelligence operations, corporate espionage, or blackmail campaigns conducted by various entities who are granted access to the stolen information.
No specific indicators of compromise were provided in the source articles.
To detect activity related to this threat actor, security teams should monitor for:
Web Application Firewall (WAF) LogsAzure AD / Microsoft 365 Sign-in LogsEWS (Exchange Web Services)Large outbound data transfers from mail serversDetection:
D3-UGLPA: User Geolocation Logon Pattern Analysis)D3-NTA: Network Traffic Analysis)Response:
D3-MFA: Multi-factor Authentication)D3-SU: Software Update)D3-SPP: Strong Password Policy)Enforce MFA on all email accounts to prevent takeovers via password guessing or spraying.
Regularly patch all internet-facing systems to defend against vulnerability scanning and exploitation.
Continuously monitor M365 and Exchange logs for signs of anomalous access or data exfiltration.
Implement strong password policies and block common passwords to make guessing attacks more difficult.
Approximate start date of the hacking campaign.
The FBI disrupted the 'Raptor Train' botnet, also controlled by Integrity Technology Group.
A joint international advisory is released detailing the group's activities.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.