Cybersecurity2 hrs ago

Seven nations say Integrity Tech hacking is ongoing, but advisory gives no breach count

The FBI seized seven domains linked to Integrity Technology Group. A seven-nation advisory describes the hacking in the present tense, with no breach count.

Peter Olaleru/3 min/US

Published October 9, 2026

Editor & Founder

TweetLinkedIn
Seven nations say Integrity Tech hacking is ongoing, but advisory gives no breach count
Credit: UnsplashOriginal source

The FBI announced on October 8, 2026 that it had seized seven web domains linked to hacking tools allegedly operated by Integrity Technology Group, a Chinese security firm. The same day, agencies from the United States, United Kingdom, Australia, Canada, Japan, New Zealand, and Spain issued a joint advisory warning that China-linked attackers enabled by Integrity Tech use botnets, malware, and intrusion tools to target organizations worldwide and steal sensitive data, including from US critical infrastructure.

According to the seven governments, the hackers scanned a South Carolina power company's network and other critical infrastructure for vulnerabilities. They exploited flaws using scanning tools, cross-site scripting, and password spraying against Microsoft Exchange servers. They established persistence through VPN software and exfiltrated email. The activity has been ongoing since at least mid-January 2021, and the advisory describes it in the present tense. It provides no date for any theft and does not specify how many organizations were breached.

The reported victims span government organizations, law enforcement, healthcare systems, and religious institutions in Southeast Asia. The hackers also ran a web application that provided third-party access to stolen email. Integrity Technology Group has been sanctioned by both the US and the UK.

The domain seizure is a visible enforcement action. The advisory's present-tense framing is the more consequential signal: it implies the espionage campaign and its enabling infrastructure are not fully neutralized. The tools described are commodity-adjacent — scanning scripts, password spraying, VPN persistence — rather than exotic zero-days. That lowers the barrier to entry for copycat actors and means the defensive lessons apply broadly.

This campaign is distinct from a separate suspected Chinese espionage group, TA419, which impersonated AI policy figures in phishing campaigns targeting US universities, think tanks, and law firms in July 2026.

Sources

- https://www.theregister.com/security/2026/10/08/us-disrupts-chinese-hacking-tools-as-7-govts-warn-of-prc-spies-stealing-sensitive-data-worldwide/5302107 - https://thehackernews.com/2026/10/fbi-says-china-linked-hackers-ran.html - https://www.theregister.com/security/2026/10/01/suspected-chinese-spies-spoofed-an-anthropic-exec-ex-white-house-official-in-ai-phishing/5300595

TweetLinkedIn

More in this thread

Reader notes

Loading comments...