China-Linked Hackers Ran Portal for Stolen Data

FBI: China-Linked Hackers Gave Third Parties Access to Stolen Emails

HIGH
October 8, 2026
6m read
Threat ActorData BreachCyberattack

Related Entities

Organizations

Other

Integrity Technology GroupRaptor Train

Full Report

Executive Summary

A joint advisory from the FBI and partner agencies from six other nations has exposed new details about a hacking campaign conducted by actors associated with the sanctioned Chinese cybersecurity company, Integrity Technology Group. The advisory, released on October 8, 2026, reveals that the threat actors not only stole vast amounts of email data but also operated a web application that provided third-party access to the stolen content. The campaign, active since at least mid-January 2021, targeted a broad spectrum of organizations across North America, Southeast Asia, and Africa. Victims included government agencies, law enforcement, healthcare systems, and critical manufacturing. This operation highlights a potential 'hacker-for-hire' model where stolen data is productized and made available to other entities.

Threat Overview

The campaign is attributed to actors linked to Integrity Technology Group, a company previously sanctioned by the U.S. and U.K. for its malicious cyber activities. The group's primary objective was the large-scale theft of email communications from targeted organizations. The scope of targeting was extensive, encompassing government services, critical manufacturing, healthcare, IT, law enforcement, education, and religious institutions in the United States alone.

A key and highly concerning finding from the advisory is the existence of a web portal operated by the hackers. This portal served as a repository for the stolen email content and provided access to unidentified third parties. This suggests a sophisticated operation that goes beyond simple intelligence gathering, potentially offering a 'data-access-as-a-service' to other actors, which could include other intelligence services or commercial entities.

The FBI's insights are based on evidence recovered during multiple investigations, including the disruption of the 'Raptor Train' botnet in September 2024, which was also controlled by Integrity Technology Group.

Technical Analysis

The threat actors employed a multi-pronged approach to gain access and exfiltrate data from target networks.

Intrusion Methods

  1. Vulnerability Scanning: The group used a custom tool containing over 1,300 scripts to scan public-facing websites and applications for vulnerabilities. This allowed them to identify and exploit weaknesses for initial access.
  2. Password Guessing: The attackers conducted brute-force or password-spraying attacks against Microsoft 365 and Microsoft Exchange accounts to gain access through weak or compromised credentials.
  3. Data Exfiltration: Once inside an account, the hackers used specialized tools designed to copy and exfiltrate entire mailboxes, ensuring they captured all historical and incoming communications.

MITRE ATT&CK Techniques

Impact Assessment

The impact of this campaign is significant due to its scale, the sensitivity of the targeted sectors, and the novel data-sharing model. For the breached organizations, the theft of email communications can expose sensitive government information, trade secrets, intellectual property, and personal data. The targeting of law enforcement and healthcare has serious implications for public safety and privacy.

The existence of a portal for third-party access represents a major escalation. It indicates that the stolen data is not just being used by the primary threat actor but is being disseminated, multiplying the potential for harm. This could enable parallel intelligence operations, corporate espionage, or blackmail campaigns conducted by various entities who are granted access to the stolen information.

IOCs — Directly from Articles

No specific indicators of compromise were provided in the source articles.

Cyber Observables — Hunting Hints

To detect activity related to this threat actor, security teams should monitor for:

Type
Log Source
Value
Web Application Firewall (WAF) Logs
Description
Look for broad and noisy scanning activity from a single source IP or ASN, especially probes against a wide range of vulnerabilities.
Type
Log Source
Value
Azure AD / Microsoft 365 Sign-in Logs
Description
Monitor for high rates of failed logins (password spraying) or successful logins from anomalous or non-corporate IP addresses.
Type
API Endpoint
Value
EWS (Exchange Web Services)
Description
Anomalous usage of EWS, especially by unfamiliar tools or scripts, can be an indicator of mailbox enumeration and exfiltration.
Type
Network Traffic Pattern
Value
Large outbound data transfers from mail servers
Description
Unexplained large data flows from Exchange servers to external IP addresses could signify mailbox theft.

Detection & Response

Detection:

  1. Authentication Monitoring: Implement robust monitoring of Microsoft 365 and Exchange logs. Alert on impossible travel, suspicious login locations, and high-volume password guessing or spraying attacks. (D3FEND: D3-UGLPA: User Geolocation Logon Pattern Analysis)
  2. Application Auditing: Regularly audit permissions for applications with access to mailboxes (e.g., via EWS or Microsoft Graph API). Look for suspicious or overly permissive applications.
  3. Network Data Analysis: Analyze NetFlow or other network telemetry to spot unusual data transfers from mail servers to external destinations. (D3FEND: D3-NTA: Network Traffic Analysis)

Response:

  1. Account Lockout: If an account is compromised, immediately disable it, revoke all sessions, and force a password reset.
  2. Block Malicious IPs: Block any IP addresses identified as being part of the attack infrastructure.
  3. Scope the Breach: Investigate mailbox audit logs to determine which mailboxes were accessed and what data was exfiltrated.

Mitigation

  • Enforce MFA: The single most effective mitigation against password-based attacks is to enforce phishing-resistant Multi-Factor Authentication (MFA) on all accounts, especially for email. (D3FEND: D3-MFA: Multi-factor Authentication)
  • Patch Public-Facing Systems: Maintain an aggressive patch management program for all internet-facing applications and servers to reduce the attack surface available for scanning. (D3FEND: D3-SU: Software Update)
  • Disable Legacy Protocols: Disable legacy authentication protocols (e.g., POP, IMAP, SMTP AUTH) in Exchange Online that do not support MFA.
  • Strong Password Policies: Implement and enforce strong password policies to make password guessing more difficult. (D3FEND: D3-SPP: Strong Password Policy)

Timeline of Events

1
January 15, 2021
Approximate start date of the hacking campaign.
2
September 1, 2024
The FBI disrupted the 'Raptor Train' botnet, also controlled by Integrity Technology Group.
3
October 8, 2026
A joint international advisory is released detailing the group's activities.
4
October 8, 2026
This article was published

MITRE ATT&CK Mitigations

Enforce MFA on all email accounts to prevent takeovers via password guessing or spraying.

Regularly patch all internet-facing systems to defend against vulnerability scanning and exploitation.

Audit

M1047enterprise

Continuously monitor M365 and Exchange logs for signs of anomalous access or data exfiltration.

Implement strong password policies and block common passwords to make guessing attacks more difficult.

Timeline of Events

1
January 15, 2021

Approximate start date of the hacking campaign.

2
September 1, 2024

The FBI disrupted the 'Raptor Train' botnet, also controlled by Integrity Technology Group.

3
October 8, 2026

A joint international advisory is released detailing the group's activities.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

fbichinaaptdata breachmicrosoft 365exchangeintegrity technology groupespionage

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

⚡ Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.