Security Advisory · October 8, 2026

China-linked hackers are going after business email. Here's what to do this week.

A new joint advisory from the FBI, CISA, NSA and partner agencies in seven other countries describes a years-long campaign of webmail password spraying and mailbox theft. Here's what it means for small and mid-sized businesses.

What was announced

On October 8, 2026, CISA published advisory AA26-281A, co-sealed by the FBI, NSA and cyber agencies in the UK, Australia, Canada, Japan, New Zealand and Spain. It attributes a long-running hacking campaign to Integrity Technology Group, a China-based company with links to the Chinese government. Security researchers also track the activity as Flax Typhoon, Ethereal Panda and Red Juliett.

The victims include government agencies, law enforcement, healthcare, manufacturing, IT providers, schools and religious organizations. Most of the confirmed data theft was in Southeast Asia, but the targets also include North America.

Why this is an email story

Most of the advisory describes attacks on email accounts and mailboxes. Three techniques stand out.

1. Password spraying against webmail

The attackers use an open-source tool called EBurst to guess passwords against Microsoft Exchange and Office 365. It attacks ten different login points, including Outlook on the web, ActiveSync (phones), Autodiscover and Exchange Web Services. Password spraying tries a few common passwords against many accounts, so it often stays under lockout thresholds. If MFA only protects the browser login and not ActiveSync or EWS, those other login points stay open.

2. Quiet, automated mailbox theft

Once in, the attackers don't need to stay logged in. One tool pulls mail through Exchange Web Services, compresses and encrypts it, and uploads it to their servers. Another, called office-cli, keeps automated access to Microsoft 365 mailboxes using stolen cloud application credentials. Changing a user's password does not revoke that kind of app access. You have to find and remove the app.

3. Fake login boxes on real websites

The attackers injected code into legitimate but vulnerable websites. The code showed visitors a fake username and password prompt, then offered a password-protected ZIP file. Inside was malware disguised as a Windows diagnostics program (DiagTrack.exe) that goes after the victim's email data. Password-protected archives are a common trick because many scanners can't look inside them.

It's not just email

The advisory lists eight vulnerabilities the group has exploited. Every one is old and already patched: Pulse Connect Secure VPN (CVE-2019-11510), GitLab (CVE-2021-22205), Apache Struts, ProFTPD, ISC BIND, GNU Bash "Shellshock", ONLYOFFICE DocumentServer and Strapi. In other words, they got in through systems that were never updated or were past end of life. The group also installs SoftEther VPN software, renamed to look like Windows system files, to keep a back door open, and it steals Active Directory credentials with a DCSync tool.

What to do this week

These steps are drawn from the advisory's own recommendations, in the order we'd do them.

  1. Turn on MFA for every way into email, not just the web login. Check phones (ActiveSync), desktop clients and any legacy protocols. If a protocol can't do MFA and nobody needs it, turn it off.
  2. Review connected apps in Microsoft 365 or Google Workspace. Remove any application with mailbox or file access that you don't recognize. This is the step a password reset won't cover.
  3. Alert on unusual sign-ins: logins outside business hours, "impossible travel" between distant locations, and bursts of failed logins across many accounts.
  4. Patch or replace internet-facing systems. VPNs, web apps, Git servers and document servers come first. Retire anything that no longer gets updates.
  5. Close what you don't use. Disable unused ports and services, and remove version details from login pages and banners.
  6. Use protective DNS and browser download screening so a click on a bad link or file is caught even when it doesn't arrive by email.
  7. Treat password-protected attachments and downloads with suspicion. Tell staff that a "secure ZIP" from an unexpected source is a red flag, not a reassurance.
  8. Keep backups the source system can't change. Hold multiple copies in separate locations, with at least one that an attacker inside your network can't modify or delete.

Where EFA fits, and where it doesn't

We think you should know what a product covers and what it doesn't.

  • A mail gateway does not stop password spraying. EBurst attacks your mailbox server's login pages directly, and that traffic never passes through an inbound filter like OpenEFA. MFA and sign-in monitoring are the defense there.
  • A gateway does help with what arrives in the inbox: phishing links, look-alike login pages and malicious attachments that try to start the same chain of events by email.
  • Monitoring and backups cover the rest. EFAsentry watches for account-compromise indicators and OAuth-based intrusions across the email path, the kind of app-based access this campaign relies on. EFAlifeline keeps mailbox backups outside your email platform, so someone with mailbox access can't tamper with them too.

No single product covers all of it. That's why the advisory lists nineteen mitigations, not one.

If you think you've been hit

Isolate the affected machines, keep the logs, and report it: in the US to the FBI (ic3.gov) or CISA (cisa.gov/report). The full advisory includes indicators of compromise (domains, IP addresses and file hashes) in STIX format for your security team or provider. CISA notes that many of those indicators are years old, so check them before blocking.

Source: CISA, FBI, NSA et al., Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data, Advisory AA26-281A, October 8, 2026. Summary by the EFA Security team.

At a glance

  • Advisory: AA26-281A
  • Released: Oct 8, 2026
  • Actor: Integrity Technology Group (Flax Typhoon)
  • Main targets: Exchange and Microsoft 365 mailboxes, internet-facing apps
  • Top fix: MFA on every email login path

Read the source

The full advisory, with indicators of compromise and MITRE ATT&CK mappings.

CISA AA26-281A

Want a second look?

We'll go through your email setup and sign-in exposure with you.

Contact us