FBI Says Chinese Firm Helped Hackers Access Stolen Emails

FBI Stolen Email Hacking: Chinese Firm Helped Hackers | CyberPro Magazine

Key Takeaways: 

  • Federal agencies say the FBI stolen email hacking investigation revealed that hackers ran an online portal that gave others access to stolen emails.
  • The U.S.-sanctioned Chinese cybersecurity company Integrity Technology Group faces scrutiny over its alleged role.
  • Investigators found that attackers targeted government, healthcare, law enforcement, and religious organizations.

On October 8, the Federal Bureau of Investigation (FBI) and international partners revealed that hackers linked to a Chinese cybersecurity company ran an online portal that allowed third parties to access stolen emails.

FBI Uncovers China-Linked Portal For Stolen Emails

Federal investigators reported that the FBI stolen email hacking investigation revealed a Chinese cybersecurity company ran an online portal that gave third parties access to stolen emails. The FBI and agencies from six other countries issued a joint advisory detailing the activity.

According to the advisory, the hackers targeted government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia.

The attackers have been breaking into government and corporate networks since at least mid-January 2021. Users of the unauthorized web application could view emails from specific accounts by changing details in a web address.

The U.S. Treasury Department sanctioned Integrity Technology Group in January 2025 over its alleged involvement in computer break-ins. The United Kingdom imposed separate sanctions in December 2025. Chinese officials opposed the actions taken by Western governments.

Hackers Exploited Software Flaws To Break Into Networks

The hackers searched websites for known security flaws using custom command-line tools. These tools included scripts written in programming languages such as Python and Go.

Investigators found that the attackers used eight known software flaws to break into systems and gain access to more networks.

The hackers also used fake login pages to steal users’ login details. They used a technique called cross-site scripting to change vulnerable web pages and display fake fields asking for usernames and passwords.

After gaining access, the attackers downloaded databases or manually collected email data. Their access was restricted to specific internet addresses located in Xiamen, China.

Agencies Recommend Ways To Protect Organizations

Cybersecurity agencies urged organizations to check their networks for signs of the reported activity. They recommended turning off unused services and remote access ports to reduce the number of ways attackers could enter their systems.

Organizations investigating FBI stolen email hacking should also check and clean up information submitted through web applications to prevent cross-site scripting attacks.

Agencies recommended requiring multifactor authentication on important systems, webmail accounts, and virtual private networks (VPNs). Security teams should regularly review application logs and install updates that fix known software flaws.

Organizations should also check cloud accounts for connected applications, look for unexpected Active Directory replication activity, and replace software products that no longer receive security updates.

Visit more of our news! CyberPro Magazine

LinkedIn
Twitter
Facebook
Reddit
Pinterest