NEWS

FBI, Allies Expose China-Linked Flax Typhoon Portal Selling Stolen Email Access

FBI and 6 allied nations say China's Integrity Tech ran a portal selling access to emails stolen from Southeast Asian governments and healthcare systems.

Dylan H.

News Desk

October 8, 2026
7 min read
FBI, Allies Expose China-Linked Flax Typhoon Portal Selling Stolen Email Access

FBI and Six-Nation Coalition Expose Flax Typhoon's Stolen-Email Access Portal

On October 8, 2026, the FBI, CISA, and the NSA — joined by cyber agencies from six other countries — published a joint advisory (AA26-281A) revealing that a Beijing-based contractor called Integrity Technology Group ("Integrity Tech") operated a web portal that handed third parties direct access to an archived database of stolen email content. Victims span government bodies, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia, plus additional targets in the United States, Africa, and North America. The advisory ties Integrity Tech directly to Flax Typhoon (also tracked as RedJuliett and Ethereal Panda), a Chinese state-sponsored group active since at least January 2021, and arrives alongside a DOJ/FBI seizure of multiple websites hosting the group's hacking tools.


AttributeValue
Enabling companyIntegrity Technology Group ("Integrity Tech"), Beijing
Linked threat actorFlax Typhoon (aka RedJuliett, Ethereal Panda)
Advisory designationCISA AA26-281A
Lead agencyFBI, with CISA and NSA
Co-signing nationsUnited Kingdom, Australia, Canada, Japan, New Zealand, Spain
Campaign timeframeActive since at least January 2021; indicators date to 2016
Prior sanctionsUS Treasury OFAC (January 2025), United Kingdom (December 2025)
Victim sectorsGovernment, law enforcement, healthcare, religious institutions, critical manufacturing, IT, education
Primary geographySoutheast Asia, with additional victims in the US, Africa, and North America
Enforcement actionDOJ/FBI seizure of websites hosting Microscan and FishHub tooling

How the Portal Worked

Reconnaissance and Initial Access

Integrity Tech built and maintained MicroScan, a Python-based scanning platform packed with more than 1,300 penetration-testing scripts, which the advisory says Integrity Tech's government-linked clients used to probe target networks for exploitable weaknesses. Investigators tied MicroScan scanning activity to a South Carolina power utility, airports in Japan and Poland, Taiwanese natural gas and power companies, two Taiwanese universities, and a multinational non-governmental organization. Once a target's weak points were mapped, operators used password-spraying tools such as EBurst against Microsoft 365 and Exchange accounts, combined with cross-site scripting and credential-harvesting techniques, to gain an initial foothold.

Mailbox Harvesting

After breaching a network, the hackers deployed purpose-built exfiltration tools — including office-cli, a command-line utility for pulling mail out of Outlook 365, and a PHP script that interfaces directly with Microsoft's Exchange Web Services (EWS) API — to copy entire mailboxes wholesale. A separate tool performed DCSync replication against Active Directory domain controllers to harvest credentials and move laterally. According to Justice Department filings, a second toolset known as FishHub supported deceptive phishing emails and delivered follow-on malware that let Integrity Tech's clients remotely browse a compromised network, search for specific files, and exfiltrate them to company-controlled servers — with roughly 20 Taiwanese universities confirmed as FishHub victims.

The Stolen-Email Portal

The advisory's most notable finding is a web application, run by Integrity Tech, that gave third parties access to an archived database of stolen email content. Users retrieved specific mailboxes by appending arguments directly to a URL rather than through any conventional storefront, and access to the portal was restricted to IP addresses originating from Xiamen, China — a detail the agencies frame as evidence of tightly controlled distribution to vetted clients rather than an open criminal marketplace. The joint advisory does not identify who the downstream recipients of the stolen mail were, describing Integrity Tech broadly as a "for-profit" enabler that supplies scanning, intrusion, and exfiltration capability to China-linked state threat actors on a client basis.

Infrastructure and Prior Groundwork

Flax Typhoon's access built on groundwork laid years earlier. The group previously ran the Raptor Train botnet — a network of more than 200,000 hijacked routers, firewalls, NAS devices, and other IoT hardware — which the FBI disrupted in September 2024. That botnet gave MicroScan a base of compromised relay points from which to launch reconnaissance without directly exposing Integrity Tech's own infrastructure.


Impact AreaDescription
Government/diplomaticEmail of government and law enforcement agencies across Southeast Asia exposed to unidentified third-party access
HealthcareHealthcare system mailboxes harvested, raising patient-data and operational-continuity concerns
Religious institutionsCommunications from religious organizations collected, exposing sensitive congregant and donor data
Critical infrastructureConfirmed scanning and intrusion activity against power utilities, airports, and natural-gas operators
EducationRoughly 20 Taiwanese universities confirmed as victims of post-exploitation tooling
Attribution/deterrenceAdvisory described as the most comprehensive public attribution to date tying Flax Typhoon directly to Integrity Tech and the Raptor Train botnet

Recommendations

For Security Teams

  • Ingest the full indicator set in AA26-281A — including MicroScan, EBurst, office-cli, and the DCSync tooling named in the advisory — into detection pipelines and threat-intel platforms.
  • Hunt for unauthorized SoftEther VPN installations, which the advisory identifies as a persistence mechanism used after initial compromise.
  • Patch and closely monitor internet-facing edge devices (VPN concentrators, routers, firewalls) — the advisory notes these are consistently the actors' preferred entry point because they receive less monitoring than core infrastructure.

For Email and IT Administrators

  • Enforce multi-factor authentication and Conditional Access policies on all Microsoft 365 and Exchange accounts, with lockout thresholds tuned against password-spraying patterns.
  • Audit Exchange Web Services (EWS) API usage logs for anomalous bulk-mailbox-access patterns consistent with automated exfiltration scripts.
  • Monitor for DCSync-style replication requests from unexpected hosts, a strong indicator of Active Directory credential harvesting.

For Government, Healthcare, and Religious Organizations in Southeast Asia

  • Treat this advisory as a prompt to assume compromise if any published indicators match internal telemetry, and begin incident-response triage rather than waiting for confirmation of data sale.
  • Rotate credentials for all service accounts and administrators tied to email infrastructure, prioritizing accounts with EWS or mailbox-export permissions.
  • Engage national CERTs and the co-signing agencies (FBI, NCSC-UK, ASD's ACSC, the Canadian Centre for Cyber Security, Japan's NPA/NCO, NCSC-NZ, and Spain's CNI) for sector-specific guidance and indicator sharing.

Key Takeaways

  1. The FBI, CISA, NSA, and six partner nations jointly attributed a stolen-email access portal to Integrity Technology Group, a sanctioned Chinese contractor tied to Flax Typhoon.
  2. The portal restricted access to IP addresses from Xiamen, China, suggesting controlled distribution to vetted clients rather than an open criminal marketplace.
  3. Confirmed victims include Southeast Asian government bodies, law enforcement agencies, healthcare systems, and religious institutions, alongside critical-infrastructure targets in the US, Taiwan, Japan, and Poland.
  4. The campaign has run since at least January 2021, building on infrastructure and a 200,000-device IoT botnet (Raptor Train) that the FBI disrupted in September 2024.
  5. The DOJ and FBI seized websites hosting the group's Microscan and FishHub tooling on October 8, 2026, alongside the publication of advisory AA26-281A.
  6. Integrity Tech was already under US Treasury (January 2025) and UK (December 2025) sanctions before this advisory, which the agencies describe as the most comprehensive public attribution of Flax Typhoon to date.

Sources