Jessica Entwistle
October 9 2026
The National Cyber Security Centre has published a joint advisory with international partners, including the FBI and agencies from Australia, Canada, Germany, Japan and New Zealand, warning that China-linked threat actors have been targeting organisations across multiple sectors globally to steal sensitive data. The activity, attributed to actors associated with Chinese cybersecurity company Integrity Technology Group, involved scanning websites for vulnerabilities and exploiting weaknesses to gain access to email systems and other sensitive information. Targets included government organisations, law enforcement agencies, healthcare systems and religious institutions, primarily in Southeast Asia. The advisory states that the threat actors operated a portal allowing third parties to access stolen data, and that the activity has been ongoing for several years.
This advisory reinforces the persistent and coordinated nature of nation-state targeting, particularly for organisations that operate internationally, hold sensitive data or work with partners in affected regions. The fact that compromised data was made accessible through a shared platform suggests a commercialised model of cyber espionage, where stolen information may be distributed beyond the original attackers. This increases the risk that UK organisations with operations or partnerships in Southeast Asia or other targeted regions may find their data exposed through supply chain or partner compromise, even if they were not directly targeted themselves. The advisory highlights the importance of understanding where sensitive data sits, who has access to it, and how third-party relationships may introduce risk. For organisations in sectors such as government, healthcare, legal, defence or critical infrastructure, the targeting patterns described in the advisory are directly relevant and should inform defensive priorities.
UK organisations should review how email security, web application security and access controls are managed, particularly for systems that handle sensitive or commercially valuable information. Consider whether there is visibility of scanning activity against public-facing systems, whether multi-factor authentication is enforced for email and administrative access, and whether threat intelligence about targeting patterns is being used to inform defensive priorities. Organisations should also consider whether they have processes in place to assess the security posture of international partners or third parties that may be targeted by similar activity. Where sensitive data is shared with or accessible by partners in higher-risk regions, consider whether additional controls, monitoring or contractual assurances are appropriate. This is also a prompt to review whether incident response plans account for the possibility of compromise through a trusted third party rather than direct targeting.
Source: NCSC UK