FBI and six nations tie Beijing's Integrity Tech to government email theft
On October 8, 2026, the FBI and cyber agencies from six allied nations issued joint advisory AA26-281A, identifying Beijing-based Integrity Technology Group as enabling years of intrusions into government, law enforcement, healthcare and religious networks across three continents. The actors built a custom portal that let third parties query stolen mailboxes via URL, with access in some cases limited to IPs from Xiamen, China.
- Joint advisory AA26-281A was co-signed by CISA, NSA, NCSC and agencies from Australia, Canada, Japan, New Zealand and Spain
- The email theft campaign has run since at least mid-January 2021, with indicators dating back to 2016
- Integrity Tech has been sanctioned by the US since January 2025, the UK since December 2025 and the EU since March 2026
- In 2024 the FBI linked the company to the Raptor Train botnet of over 200,000 devices
Read next
Security