Most breach advisories describe what was stolen. This one also describes where it went: a web application that, according to the agencies, gives third parties access to the stolen email. On 8 October, CISA, the FBI, the NSA and partner agencies from the UK, Australia, Canada, Japan, New Zealand and Spain published advisory AA26-281A. It says Chinese government-linked actors, enabled by a company called Integrity Technology Group, have been combining automated scanning with hands-on hacking to steal email content and account credentials from government, law enforcement, healthcare, education, critical manufacturing, IT and religious organisations.
The practical point for anyone who has ever emailed a password: mail that is stolen does not stay with whoever stole it.
What the advisory says
The evidence the advisory cites was recovered during multiple FBI investigations, including a cross-site scripting payload, malware samples and an email database. The agencies say the activity overlaps with groups known as Flax Typhoon, Ethereal Panda and Red Juliett, and caution that attribution does not map one-to-one onto those names. The Hacker News reports activity dating to at least January 2021.
- Getting in. Password spraying and guessing against Exchange and Microsoft 365 sign-in pages using a tool called EBurst; XSS payloads that inject fake login fields to harvest credentials; and exploit tools for eight vulnerabilities, including older flaws in Bash, ProFTPD, Apache Struts, Pulse Connect Secure, GitLab, ONLYOFFICE and Strapi. Five of them were newly added to CISA's known-exploited list with the advisory.
- Staying in. SoftEther VPN clients disguised with ordinary Windows-looking file names, and web shells.
- Taking credentials. DCSync, a technique that copies credentials and group data out of Active Directory by pretending to be a domain controller.
- Taking mail. A tool for continuous automated access to Microsoft 365 mailboxes, and a PHP bot that uses Exchange Web Services to collect, compress and encrypt mail before sending it out.
- The portal. A custom web application that “provides third-party access to stolen email content.” Per The Hacker News, a specific account's mail could be viewed by adding arguments to a URL, and in some cases access was limited to addresses in Xiamen, China.
What is not known
- Who the third parties are. The advisory does not identify them.
- How many organisations were affected, which break-ins belong to which group, and when the thefts happened. The advisory gives no victim count and no theft dates.
- The company's position. Integrity Technology Group denied US accusations in January 2025 after sanctions. We did not find a response to this advisory.
- The role of AI. One national cyber centre is reported to say the actors use AI tools, without the report saying which; the advisory itself does not mention AI, so we leave that aside.
- Indicator quality. The Hacker News notes some indicators date to 2016 and that some addresses overlap with a 2024 botnet advisory with conflicting dates. Check indicators before you block on them.
Why a stolen mailbox is a secrets problem
A mailbox is a long-lived archive that nobody curated. Over the years it collects password resets, temporary credentials, wifi keys, forwarded tokens, scanned documents and screenshots. When an actor takes mail wholesale and makes it searchable for other parties, the question is not whether any of that is sensitive but how much of it is still live.
The same advisory describes theft of Active Directory credentials, so the two sets of material reinforce each other: the passwords found in mail can be tried against directory accounts, and directory data tells the reader whose mailbox to read next.
What to do
- Block the easy way in. Require multi-factor authentication, ideally phishing-resistant, on webmail, VPN and Microsoft 365. Rate-limit and alert on password spraying, which shows up as many failed sign-ins across many accounts from few sources.
- Patch or retire the old exposed software. The listed flaws date from 2014 to 2023. If you run any of those products on the internet, they are the cheapest fix on this list.
- Hunt for the quiet things. The advisory suggests watching for unexpected Active Directory replication, which is the sign of DCSync, for unusual outbound traffic and for abnormal sign-ins, and for reviewing cloud applications that have mailbox or file access. Review web and firewall logs for the XSS and exploit activity it describes.
- Treat mailboxes of suspected victims as exposed. Search them for credentials that are still live, such as passwords, API keys, recovery codes and shared logins, and rotate those, starting with anything privileged.
- If DCSync is suspected, plan for a directory-wide reset. That includes service accounts and, as standard Active Directory recovery practice rather than a step from this advisory, the krbtgt account. Do it in an order your directory team has rehearsed, because mistakes lock people out.
- Review mail rules, forwarding and delegated access. Persistence in Microsoft 365 often lives in settings rather than malware.
- Stop putting secrets in mail from now on. If every future password you send is a link that expires, the next stolen archive contains less. This is the habit change with the largest long-term effect.
Where Secretus fits, and where it does not
Secretus is for the last step. A person encrypts a short text secret in the browser and shares a link that stops working after the expiry they set or the first successful open, so the email carries a link rather than the password itself. Send the link and the context through different channels for anything sensitive. Team Split can require several holders to reconstruct a high-value text secret.
It is not an email security product or an incident response tool. It cannot stop password spraying, detect DCSync, clean credentials out of existing mailboxes, or tell you whether your organisation is among the victims. Do those with your identity and security tooling, and use a one-time link so the next secret is not added to the archive.
