China-Linked Hackers Built Commercial Portal to Resell Stolen Government Emails
The Integrity Technology Group conducted a years-long campaign stealing emails from high-value targets including government, law enforcement, and healthcare organizations, operating at least since January 2021 before detection. Most critically, the threat actors commoditized the stolen data by building a portal that granted paying third parties direct access to the exfiltrated communications, dramatically amplifying the harm beyond the initial breach. This case illustrates how insufficient email security controls, poor visibility into abnormal data exfiltration patterns, and delayed detection allowed a sophisticated actor to operate unimpeded for years. The existence of a commercial resale portal means downstream victims may be exposed to threats from multiple actors, not just the original attacker, compounding the long-term risk to affected organizations.
Tactical Insight
Immediate actions
- Audit and enforce multi-factor authentication (MFA) on all email platforms, especially internet-facing access points like OWA or webmail portals.
- Conduct a threat hunt across email gateway logs for signs of large-scale, anomalous data exfiltration consistent with bulk email harvesting.
- Review and restrict third-party and delegated access permissions within your email environment (e.g., Exchange delegate access, OAuth app permissions).
Detection measures
- Deploy User and Entity Behavior Analytics (UEBA) to flag abnormal email access patterns such as mass downloads, forwarding rules, or access from unusual geolocations.
- Implement Data Loss Prevention (DLP) rules specifically targeting bulk email exfiltration attempts via SMTP, HTTPS, or API channels.
- Enable comprehensive audit logging for all email access events and ensure logs are retained for a minimum of 12 months in a tamper-resistant SIEM.
Long-term improvements
- Adopt a Zero Trust architecture that continuously validates identity and device posture before granting access to sensitive communications infrastructure.
- Establish formal threat intelligence sharing partnerships (e.g., ISACs) to receive early warning of nation-state targeting campaigns relevant to your sector.
- Conduct regular purple team exercises simulating email exfiltration scenarios to validate detection and response capabilities against advanced persistent threats.