Stolen email content exposed through hacker web application
Data Leak
Summary
Hide ▲
Show ▼
A hacker-operated web application is exposing stolen email content to third parties, letting outsiders read compromised mail instead of keeping it locked inside the original breach. The portal lets users view the mail of a specific account by adding arguments to a URL. The exposure is tied to Integrity Technology Group-linked hackers and extends the impact of their mailbox theft activity.
Related Happenings
Integrity Technology Group-linked email-theft and password-spraying campaign
Campaign
H score89
First: 08.10.2026 21:32
Last: 08.10.2026 21:32
Sources 1
How related:
The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail.
About this happening:
A multi-country email-theft campaign tied to Integrity Technology Group has targeted government, law enforcement, healthcare, and religious organizations since at leas...
Integrity Technology Group-linked email-theft and password-spraying campaign
CampaignHow related: The hackers scanned websites for flaws using a tool containing more than 1,300 scripts, guessed passwords for Microsoft 365 and Exchange accounts, and copied mailboxes using tools designed to collect mail.
About this happening: A multi-country email-theft campaign tied to Integrity Technology Group has targeted government, law enforcement, healthcare, and religious organizations since at leas...
High-volume Unicode-smuggling phishing campaign
Campaign
H score29
First: 04.09.2026 18:57
Last: 04.09.2026 18:57
Sources 1
About this happening:
A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...
High-volume Unicode-smuggling phishing campaign
CampaignAbout this happening: A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The...
Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft
Technical Analysis
H score30
First: 08.08.2026 11:03
Last: 08.08.2026 11:03
Sources 1
About this happening:
PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastm...
Webmail HTML/CSS boundary-bypass research exposing password, token, and UI-action theft
Technical AnalysisAbout this happening: PortSwigger research showed HTML/CSS inside email can cross the webmail boundary and steal passwords, tokens, and trusted UI actions across Outlook, Gmail, Fastm...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
Trend
H score30
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026
TrendAbout this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...
UAT-11764 QR code phishing campaign against organizations
Campaign
H score29
First: 28.07.2026 16:00
Last: 28.07.2026 16:00
Sources 1
About this happening:
A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
UAT-11764 QR code phishing campaign against organizations
CampaignAbout this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...
Timeline
-
08.10.2026 21:32 2 articles · 2h ago
Hacker web application exposes stolen email content to third parties
Initial DisclosureA web application linked to Integrity Technology Group-associated hackers provides third-party access to stolen email content, and users can view the mail of a specific account by adding arguments to a URL. The exposure extends the impact of mailbox theft by allowing outsiders to access compromised email content rather than keeping it contained on the original systems.
Show sources
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails — thehackernews.com — 08.10.2026 21:32
- FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails — thehackernews.com — 08.10.2026 21:32