$ techbeacon▋
Phishing

FBI Reveals China-Linked Hackers Operated Portal to Distribute Stolen Southeast Asian Emails

FBI Reveals China-Linked Hackers Operated Portal to Distribute Stolen Southeast Asian Emails

The Federal Bureau of Investigation announced on Oct. 8 that a group of hackers associated with a Chinese cybersecurity firm operated an online portal that gave external parties access to thousands of stolen email messages from a range of institutions across Southeast Asia.

According to the joint statement released by the FBI and law‑enforcement partners in six other nations, the compromised communications originated from government agencies, police departments, health‑care providers and religious organizations. The attackers collected the data over an extended period before uploading it to the portal, where it could be downloaded by anyone with the appropriate link.

Investigators identified the group as being linked to Integrity Technology, a Chinese cybersecurity company that has previously been cited in U.S. intelligence reports for its proximity to state‑run hacking operations. While the firm has not been formally charged, the FBI’s findings suggest that its infrastructure was used to host the illicit repository, raising questions about the company’s role in facilitating espionage activities.

The coordinated disclosure involved agencies from the United States, Australia, Japan, Singapore, the United Kingdom and two additional unnamed partners. All parties confirmed that the breach was discovered through shared cyber‑threat intelligence, prompting a rapid response to contain the portal and notify affected entities.

Cyber‑espionage campaigns attributed to actors with ties to China have been a persistent concern for governments and private sector groups worldwide. Email accounts often contain sensitive personal data, strategic plans and internal communications, making them valuable targets for intelligence gathering and potential blackmail. The Southeast Asian region, with its growing digital economies and strategic geopolitical position, has increasingly appeared on the radar of state‑aligned threat actors.

U.S. officials said the investigation remains active and that they are working with international partners to trace the individuals who accessed the portal and to assess the full scope of the data exposure. They also urged organizations in the affected sectors to review their email security protocols, implement multi‑factor authentication, and monitor for signs of credential compromise. The episode underscores the ongoing challenges of attributing cyber incidents and the importance of cross‑border cooperation in confronting transnational hacking operations.

Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related