Seven nations say Integrity Tech hacking is ongoing, but advisory gives no breach count
The FBI seized seven domains linked to Integrity Technology Group. A seven-nation advisory describes the hacking in the present tense, with no breach count.
The FBI announced on October 8, 2026 that it had seized seven web domains linked to hacking tools allegedly operated by Integrity Technology Group, a Chinese security firm. The same day, agencies from the United States, United Kingdom, Australia, Canada, Japan, New Zealand, and Spain issued a joint advisory warning that China-linked attackers enabled by Integrity Tech use botnets, malware, and intrusion tools to target organizations worldwide and steal sensitive data, including from US critical infrastructure.
According to the seven governments, the hackers scanned a South Carolina power company's network and other critical infrastructure for vulnerabilities. They exploited flaws using scanning tools, cross-site scripting, and password spraying against Microsoft Exchange servers. They established persistence through VPN software and exfiltrated email. The activity has been ongoing since at least mid-January 2021, and the advisory describes it in the present tense. It provides no date for any theft and does not specify how many organizations were breached.
The reported victims span government organizations, law enforcement, healthcare systems, and religious institutions in Southeast Asia. The hackers also ran a web application that provided third-party access to stolen email. Integrity Technology Group has been sanctioned by both the US and the UK.
The domain seizure is a visible enforcement action. The advisory's present-tense framing is the more consequential signal: it implies the espionage campaign and its enabling infrastructure are not fully neutralized. The tools described are commodity-adjacent — scanning scripts, password spraying, VPN persistence — rather than exotic zero-days. That lowers the barrier to entry for copycat actors and means the defensive lessons apply broadly.
This campaign is distinct from a separate suspected Chinese espionage group, TA419, which impersonated AI policy figures in phishing campaigns targeting US universities, think tanks, and law firms in July 2026.
Sources
- https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107 - https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html - https://www.theregister.com/security/2026/10/01/suspected-chinese-spies-spoofed-an-anthropic-exec-ex-white-house-official-in-ai-phishing/5300595
Continue reading
More in this thread
Banks face two clocks on AI: NCSC oversight guidance and ECB's October demand
Peter Olaleru
FBI Removes Contractor After Patch Failure Exposes Employee Data
Peter Olaleru
How international cooperation led to the arrest of an alleged IRGC operative
Peter Olaleru
Conversation
Reader notes
Loading comments...