Integrity Technology Group-linked email-theft and password-spraying campaign
Campaign
Summary
Hide ▲
Show ▼
A multi-country email-theft campaign tied to Integrity Technology Group has targeted government, law enforcement, healthcare, and religious organizations since at least mid-January 2021, putting mailbox access and account security at risk. The operators used website scanning, password spraying against Microsoft 365 and Exchange, and fake-login XSS pages to gain entry. They then used tools to collect and exfiltrate mail through Exchange Web Services and other legitimate access paths. The same activity also included a portal that let third parties access stolen email content.
Related Happenings
Stolen email content exposed through hacker web application
Data Leak
H score67
First: 08.10.2026 21:32
Last: 08.10.2026 21:32
Sources 1
How related:
The hackers also run a web application that "provides third-party access to stolen email content," the advisory said.
About this happening:
A hacker-operated web application is exposing stolen email content to third parties, letting outsiders read compromised mail instead of keeping it locked inside the or...
Stolen email content exposed through hacker web application
Data LeakHow related: The hackers also run a web application that "provides third-party access to stolen email content," the advisory said.
About this happening: A hacker-operated web application is exposing stolen email content to third parties, letting outsiders read compromised mail instead of keeping it locked inside the or...
Microsoft dual phishing campaigns using CEO impersonation and passkey lures
Campaign
H score34
First: 13.09.2026 13:11
Last: 13.09.2026 13:11
Sources 1
About this happening:
Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...
Microsoft dual phishing campaigns using CEO impersonation and passkey lures
CampaignAbout this happening: Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
H score34
First: 11.09.2026 20:26
Last: 11.09.2026 20:26
Sources 1
About this happening:
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
CampaignAbout this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
Campaign
H score30
First: 30.07.2026 15:00
Last: 30.07.2026 15:00
Sources 1
About this happening:
A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
CampaignAbout this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Timeline
-
08.10.2026 21:32 2 articles · 2h ago
FBI and partners disclose Integrity Technology Group-linked email theft campaign
Initial DisclosureOn October 8, the FBI and agencies in six other countries said Integrity Technology Group-linked hackers had stolen email from government organizations, law enforcement agencies, healthcare systems, and religious institutions across Southeast Asia and other regions, and that the same operators had been breaking into networks since at least mid-January 2021 using website scanning, password spraying against Microsoft 365 and Exchange, and mailbox-collection tools.
Show sources
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails — thehackernews.com — 08.10.2026 21:32
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails — thehackernews.com — 08.10.2026 21:32