Threats & Adversaries · APT / Espionage

Integrity Technology-linked hackers turned stolen mail into a portal

The FBI and partner agencies said on October 8 that hackers linked to Integrity Technology Group have been stealing Microsoft 365 and Exchange mailboxes since at least January 2021, hitting government, healthcare, technology, manufacturing, education, law enforcement, and religious organizations across several regions. The same advisory says the activity included Southeast Asia, the U.S., Africa, and North America.

The group used a large scanner with more than 1,300 scripts, guessed account passwords, and copied mailboxes with tools meant to collect email. The important twist is a separate web application that gives third parties access to stolen email content, so the compromise does not end when the original account is cleaned up; the mail can still be read through the portal.

For Microsoft 365 and Exchange operators, that means the exposure can outlive the intrusion and keep carrying value from historic messages, attachments, and password-reset trails. The reporting does not say who the third parties are, but it does show the stolen mail is being reused as an access layer of its own.

1 source · Oct 8

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: Integrity Technology-linked hackers turned stolen mail into a portal

More from today