[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fE7hnysCVcAGpKQyAHeTDHSFIVr4Cp8CleeV2xDNUmKg":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":27,"created_at":28,"published_at":29,"article":30,"tags":34,"podcasts":53},"d9505131-1e22-4336-9c26-21806cc527ad","china-linked-hackers-built-commercial-portal-to-resell-stolen-government-emails","4628ea24-e2b1-4a3b-9926-da34a064e279","China-Linked Hackers Built Commercial Portal to Resell Stolen Government Emails","The Integrity Technology Group conducted a years-long campaign stealing emails from high-value targets including government, law enforcement, and healthcare organizations, operating at least since January 2021 before detection. Most critically, the threat actors commoditized the stolen data by building a portal that granted paying third parties direct access to the exfiltrated communications, dramatically amplifying the harm beyond the initial breach. This case illustrates how insufficient email security controls, poor visibility into abnormal data exfiltration patterns, and delayed detection allowed a sophisticated actor to operate unimpeded for years. The existence of a commercial resale portal means downstream victims may be exposed to threats from multiple actors, not just the original attacker, compounding the long-term risk to affected organizations.","**Immediate actions:**\n- Audit and enforce multi-factor authentication (MFA) on all email platforms, especially internet-facing access points like OWA or webmail portals.\n- Conduct a threat hunt across email gateway logs for signs of large-scale, anomalous data exfiltration consistent with bulk email harvesting.\n- Review and restrict third-party and delegated access permissions within your email environment (e.g., Exchange delegate access, OAuth app permissions).\n\n**Detection measures:**\n- Deploy User and Entity Behavior Analytics (UEBA) to flag abnormal email access patterns such as mass downloads, forwarding rules, or access from unusual geolocations.\n- Implement Data Loss Prevention (DLP) rules specifically targeting bulk email exfiltration attempts via SMTP, HTTPS, or API channels.\n- Enable comprehensive audit logging for all email access events and ensure logs are retained for a minimum of 12 months in a tamper-resistant SIEM.\n\n**Long-term improvements:**\n- Adopt a Zero Trust architecture that continuously validates identity and device posture before granting access to sensitive communications infrastructure.\n- Establish formal threat intelligence sharing partnerships (e.g., ISACs) to receive early warning of nation-state targeting campaigns relevant to your sector.\n- Conduct regular purple team exercises simulating email exfiltration scenarios to validate detection and response capabilities against advanced persistent threats.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25,26],"CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 AC-2 – Account Management","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 AU-6 – Audit Record Review, Analysis, and Reporting","NIST SP 800-53 SI-4 – System Monitoring","NIST CSF DE.CM-1 – Network Monitoring","NIST CSF PR.DS-5 – Protections Against Data Leaks","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of Personal Data Breach","MITRE ATT&CK T1114 – Email Collection","MITRE ATT&CK T1567 – Exfiltration Over Web Service","ITIL – Information Security Management (Incident and Access Controls)","published","2026-10-08T20:21:18.541327+00:00","2026-10-08T20:21:18.219+00:00",{"id":7,"url":31,"slug":32,"title":33},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Ffbi-says-china-linked-hackers-ran.html","fbi-says-china-linked-hackers-ran-portal-giving-third-parties-access-to-stolen-e-92f369","FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails",[35,41,47],{"id":36,"name":37,"slug":38,"description":39,"color":40},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":42,"name":43,"slug":44,"description":45,"color":46},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":48,"name":49,"slug":50,"description":51,"color":52},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]