Seven Countries Issue a Joint Cyber Warning Over Stolen Email and Passwords

Ten government cyber and law enforcement agencies in seven countries published a joint advisory on Oct. 8, 2026, describing how attackers whom the agencies say were enabled by a China-based company took email and login credentials from critical-infrastructure operators.
The ten are the FBI, CISA and the NSA in the United States, Britain's National Cyber Security Centre, and agencies in Australia, Canada, Japan, New Zealand and Spain. They say the advisory, numbered AA26-281A, is meant to let network defenders search their own systems for traces of this activity, and they published it with downloadable lists of indicators that security tools can read directly.
The authoring organizations say the material comes from technical evidence recovered during multiple FBI investigations. Victims, in their account, spanned four US critical-infrastructure sectors: government services and facilities, critical manufacturing, healthcare and public health, and information technology. They say US law enforcement agencies, schools and religious organizations were also targeted, along with organizations in Southeast Asia, Africa and North America.
In the agencies' own words, Integrity Technology Group is a China-based for-profit company with links to the Chinese government whose staff acquire and build hacking tools, host infrastructure and compromise networks worldwide. They say the operators it enables combine automated scanning, large botnets, commercial VPN software and hands-on work inside a network, and that this mix of techniques is not unique to Chinese actors.
The advisory lists eight software flaws the activity successfully exploited, in products including GNU Bash, Apache Struts, GitLab and Pulse Connect Secure. The actions the agencies put first for defenders are to turn off unused services and ports, require multifactor authentication, check what web applications accept from users, and patch on time.
Britain's NCSC says on its own news page that it and international partners exposed Integrity Tech in September 2024 as the operator of a substantial botnet used by the group known publicly as Flax Typhoon.
