FBI and Six-Nation Coalition Expose Flax Typhoon's Stolen-Email Access Portal
On October 8, 2026, the FBI, CISA, and the NSA — joined by cyber agencies from six other countries — published a joint advisory (AA26-281A) revealing that a Beijing-based contractor called Integrity Technology Group ("Integrity Tech") operated a web portal that handed third parties direct access to an archived database of stolen email content. Victims span government bodies, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia, plus additional targets in the United States, Africa, and North America. The advisory ties Integrity Tech directly to Flax Typhoon (also tracked as RedJuliett and Ethereal Panda), a Chinese state-sponsored group active since at least January 2021, and arrives alongside a DOJ/FBI seizure of multiple websites hosting the group's hacking tools.
| Attribute | Value |
|---|---|
| Enabling company | Integrity Technology Group ("Integrity Tech"), Beijing |
| Linked threat actor | Flax Typhoon (aka RedJuliett, Ethereal Panda) |
| Advisory designation | CISA AA26-281A |
| Lead agency | FBI, with CISA and NSA |
| Co-signing nations | United Kingdom, Australia, Canada, Japan, New Zealand, Spain |
| Campaign timeframe | Active since at least January 2021; indicators date to 2016 |
| Prior sanctions | US Treasury OFAC (January 2025), United Kingdom (December 2025) |
| Victim sectors | Government, law enforcement, healthcare, religious institutions, critical manufacturing, IT, education |
| Primary geography | Southeast Asia, with additional victims in the US, Africa, and North America |
| Enforcement action | DOJ/FBI seizure of websites hosting Microscan and FishHub tooling |
How the Portal Worked
Reconnaissance and Initial Access
Integrity Tech built and maintained MicroScan, a Python-based scanning platform packed with more than 1,300 penetration-testing scripts, which the advisory says Integrity Tech's government-linked clients used to probe target networks for exploitable weaknesses. Investigators tied MicroScan scanning activity to a South Carolina power utility, airports in Japan and Poland, Taiwanese natural gas and power companies, two Taiwanese universities, and a multinational non-governmental organization. Once a target's weak points were mapped, operators used password-spraying tools such as EBurst against Microsoft 365 and Exchange accounts, combined with cross-site scripting and credential-harvesting techniques, to gain an initial foothold.
Mailbox Harvesting
After breaching a network, the hackers deployed purpose-built exfiltration tools — including office-cli, a command-line utility for pulling mail out of Outlook 365, and a PHP script that interfaces directly with Microsoft's Exchange Web Services (EWS) API — to copy entire mailboxes wholesale. A separate tool performed DCSync replication against Active Directory domain controllers to harvest credentials and move laterally. According to Justice Department filings, a second toolset known as FishHub supported deceptive phishing emails and delivered follow-on malware that let Integrity Tech's clients remotely browse a compromised network, search for specific files, and exfiltrate them to company-controlled servers — with roughly 20 Taiwanese universities confirmed as FishHub victims.
The Stolen-Email Portal
The advisory's most notable finding is a web application, run by Integrity Tech, that gave third parties access to an archived database of stolen email content. Users retrieved specific mailboxes by appending arguments directly to a URL rather than through any conventional storefront, and access to the portal was restricted to IP addresses originating from Xiamen, China — a detail the agencies frame as evidence of tightly controlled distribution to vetted clients rather than an open criminal marketplace. The joint advisory does not identify who the downstream recipients of the stolen mail were, describing Integrity Tech broadly as a "for-profit" enabler that supplies scanning, intrusion, and exfiltration capability to China-linked state threat actors on a client basis.
Infrastructure and Prior Groundwork
Flax Typhoon's access built on groundwork laid years earlier. The group previously ran the Raptor Train botnet — a network of more than 200,000 hijacked routers, firewalls, NAS devices, and other IoT hardware — which the FBI disrupted in September 2024. That botnet gave MicroScan a base of compromised relay points from which to launch reconnaissance without directly exposing Integrity Tech's own infrastructure.
| Impact Area | Description |
|---|---|
| Government/diplomatic | Email of government and law enforcement agencies across Southeast Asia exposed to unidentified third-party access |
| Healthcare | Healthcare system mailboxes harvested, raising patient-data and operational-continuity concerns |
| Religious institutions | Communications from religious organizations collected, exposing sensitive congregant and donor data |
| Critical infrastructure | Confirmed scanning and intrusion activity against power utilities, airports, and natural-gas operators |
| Education | Roughly 20 Taiwanese universities confirmed as victims of post-exploitation tooling |
| Attribution/deterrence | Advisory described as the most comprehensive public attribution to date tying Flax Typhoon directly to Integrity Tech and the Raptor Train botnet |
Recommendations
For Security Teams
- Ingest the full indicator set in AA26-281A — including MicroScan, EBurst, office-cli, and the DCSync tooling named in the advisory — into detection pipelines and threat-intel platforms.
- Hunt for unauthorized SoftEther VPN installations, which the advisory identifies as a persistence mechanism used after initial compromise.
- Patch and closely monitor internet-facing edge devices (VPN concentrators, routers, firewalls) — the advisory notes these are consistently the actors' preferred entry point because they receive less monitoring than core infrastructure.
For Email and IT Administrators
- Enforce multi-factor authentication and Conditional Access policies on all Microsoft 365 and Exchange accounts, with lockout thresholds tuned against password-spraying patterns.
- Audit Exchange Web Services (EWS) API usage logs for anomalous bulk-mailbox-access patterns consistent with automated exfiltration scripts.
- Monitor for DCSync-style replication requests from unexpected hosts, a strong indicator of Active Directory credential harvesting.
For Government, Healthcare, and Religious Organizations in Southeast Asia
- Treat this advisory as a prompt to assume compromise if any published indicators match internal telemetry, and begin incident-response triage rather than waiting for confirmation of data sale.
- Rotate credentials for all service accounts and administrators tied to email infrastructure, prioritizing accounts with EWS or mailbox-export permissions.
- Engage national CERTs and the co-signing agencies (FBI, NCSC-UK, ASD's ACSC, the Canadian Centre for Cyber Security, Japan's NPA/NCO, NCSC-NZ, and Spain's CNI) for sector-specific guidance and indicator sharing.
Key Takeaways
- The FBI, CISA, NSA, and six partner nations jointly attributed a stolen-email access portal to Integrity Technology Group, a sanctioned Chinese contractor tied to Flax Typhoon.
- The portal restricted access to IP addresses from Xiamen, China, suggesting controlled distribution to vetted clients rather than an open criminal marketplace.
- Confirmed victims include Southeast Asian government bodies, law enforcement agencies, healthcare systems, and religious institutions, alongside critical-infrastructure targets in the US, Taiwan, Japan, and Poland.
- The campaign has run since at least January 2021, building on infrastructure and a 200,000-device IoT botnet (Raptor Train) that the FBI disrupted in September 2024.
- The DOJ and FBI seized websites hosting the group's Microscan and FishHub tooling on October 8, 2026, alongside the publication of advisory AA26-281A.
- Integrity Tech was already under US Treasury (January 2025) and UK (December 2025) sanctions before this advisory, which the agencies describe as the most comprehensive public attribution of Flax Typhoon to date.
Sources
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails — The Hacker News
- CISA, FBI, NSA and International Partners Warn of China-based Cybersecurity Company Enabling Threat Actors — CISA
- International coalition seizes tools used by cyber firm behind Flax Typhoon — The Record