Published: · Region: Southeast Asia · Category: cyber

Air pollution crisis in Asia
Photo: National Oceanic and Atmospheric Administration (NOAA) — via Wikimedia Commons / Wikipedia: 2026 Southeast Asian haze

China‑linked hackers ran secret portal to share stolen Southeast Asian government emails, FBI says

U.S. investigators say a China‑linked group didn’t just steal emails from Southeast Asian government, police and healthcare networks — it set up a web portal where others could browse the haul. The operation shows how long‑term espionage campaigns can quietly expose sensitive regional data far beyond the original breach.

A China‑linked hacking group quietly turned stolen inboxes from Southeast Asia into a searchable trove for third parties, according to new details from the FBI, exposing how far espionage operations can reach beyond the initial breach.

Investigators say the group not only penetrated email systems belonging to government, police and healthcare organizations across Southeast Asia but also ran a web portal that allowed outside users to access the stolen messages. In effect, an intelligence operation morphed into an illicit mail service where sensitive communications were available on demand.

The FBI assessment, summarized in a new technical report, ties the activity to a cluster of actors with links to China. The hackers reportedly used an extensive toolkit of more than 1,300 scanning scripts to probe potential victims, identify vulnerabilities and automate intrusion attempts. Those scripts are designed to look for weaknesses in exposed services — mail servers, web interfaces, remote‑access tools — that can serve as footholds into larger networks.

Victims named in the disclosure include government ministries, law‑enforcement bodies and healthcare providers in multiple Southeast Asian countries. The report does not specify which states were hit, but the cluster of targets points to a focus on both political decision‑making and sensitive personal data. Healthcare records can be particularly valuable for tracking the movements and vulnerabilities of officials and security personnel.

For civil servants, police officers and doctors in the affected institutions, this kind of breach is not an abstract cyber event. It can expose internal investigations, diplomatic correspondence, informant identities, criminal records, and the private medical histories of patients who never agreed to have their files swept into a foreign archive. The existence of a browsing portal compounds the risk: access may have extended well beyond the original operators, making it harder to contain the leak.

Strategically, the operation offers a window into how modern espionage differs from the familiar model of one service quietly hoarding what it steals. By building a platform where third parties could search stolen government emails, the group created an information market of sorts, where data could be leveraged by multiple actors for political, commercial or intelligence purposes. That multiplies the potential damage for Southeast Asian states already navigating fraught relations with Beijing over maritime disputes, trade and security ties.

For China, which routinely denies involvement in state‑backed hacking, the allegation feeds into a broader pattern documented by Western agencies over the past decade: long‑term, targeted campaigns against ministries, parliaments, telecom operators and critical infrastructure abroad. Southeast Asia, sitting at the intersection of U.S.–China rivalry, major sea lanes and key technology supply chains, is a natural theater for such efforts.

The tools described by the FBI also show how the line between advanced persistent threats and more mundane cybercrime continues to blur. A library of 1,300 scanning scripts would allow operators to move quickly across thousands of potential targets, sharing or repurposing components as needed. Once a portal exists, questions arise about who exactly is on the other side of the login screen — state analysts, contractors, or criminal partners.

One takeaway from this case is straightforward and uncomfortable: securing email servers is no longer just about spam filters and password hygiene; it is about denying adversaries the ability to turn a country’s internal conversations into a searchable intelligence product.

Next steps to watch include how Southeast Asian governments publicly respond, whether any name specific suspects or request assistance from allies, and whether allied cyber agencies release indicators that allow organizations worldwide to check if the same portal or scanning scripts were used against them.

Sources