Skip to content
See the World Through ScienceA project of ALLATRA

Seven Countries Issue a Joint Cyber Warning Over Stolen Email and Passwords

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Blue, beige, green, yellow and red patch cables plugged into the front ports of a rack mounted ethernet switch, with link lights glowing between them.
Patch cables feed a rack switch. Among the first actions the agencies list for defenders is to disable unused services and ports (illustrative)."Ethernet switch" by Open Grid Scheduler / Grid Engine, via flickr, CC0

Ten government cyber and law enforcement agencies in seven countries published a joint advisory on Oct. 8, 2026, describing how attackers whom the agencies say were enabled by a China-based company took email and login credentials from critical-infrastructure operators.

The ten are the FBI, CISA and the NSA in the United States, Britain's National Cyber Security Centre, and agencies in Australia, Canada, Japan, New Zealand and Spain. They say the advisory, numbered AA26-281A, is meant to let network defenders search their own systems for traces of this activity, and they published it with downloadable lists of indicators that security tools can read directly.

The authoring organizations say the material comes from technical evidence recovered during multiple FBI investigations. Victims, in their account, spanned four US critical-infrastructure sectors: government services and facilities, critical manufacturing, healthcare and public health, and information technology. They say US law enforcement agencies, schools and religious organizations were also targeted, along with organizations in Southeast Asia, Africa and North America.

In the agencies' own words, Integrity Technology Group is a China-based for-profit company with links to the Chinese government whose staff acquire and build hacking tools, host infrastructure and compromise networks worldwide. They say the operators it enables combine automated scanning, large botnets, commercial VPN software and hands-on work inside a network, and that this mix of techniques is not unique to Chinese actors.

The advisory lists eight software flaws the activity successfully exploited, in products including GNU Bash, Apache Struts, GitLab and Pulse Connect Secure. The actions the agencies put first for defenders are to turn off unused services and ports, require multifactor authentication, check what web applications accept from users, and patch on time.

Britain's NCSC says on its own news page that it and international partners exposed Integrity Tech in September 2024 as the operator of a substantial botnet used by the group known publicly as Flax Typhoon.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Seven Countries Issue a Joint Cyber Warning Over Stolen Email and Passwords

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.