Threat advisory · Multiple

Canada and allies warn of China-linked attacks on Microsoft 365 and web servers

On Oct 8, 2026 Canada's Cyber Centre and allies warned a China-linked firm is password-spraying Microsoft 365. Turn on MFA and patch web servers.

On October 8, 2026, the Canadian Centre for Cyber Security and agencies in six other countries warned that hackers working for Integrity Technology Group, a China-based company, are guessing Microsoft 365 and Exchange passwords and exploiting unpatched web servers to steal email and data. The most useful step: require multi-factor authentication on every email account.

What happened

On Thursday, October 8, 2026, the U.S. Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) published a joint cybersecurity advisory (AA26-281A) with partners in the United Kingdom, Australia, Canada, Japan, New Zealand and Spain. Canada’s contributor is the Canadian Centre for Cyber Security (the Cyber Centre).

The advisory describes Integrity Technology Group (Integrity Tech), a company the U.S. Department of Justice says is based in the People’s Republic of China and holds Chinese government contracts. Its activity is tracked as Flax Typhoon, a campaign Microsoft first named in 2023, The Record reported.

The same day, the Department of Justice and the FBI said they had seized website domains supporting two of the company’s tools: Microscan, which scans websites for weaknesses, and FishHub, which was used to send targeted phishing emails and deliver malware.

According to the advisory, the group has:

  • used an open-source tool called EBurst to guess passwords for Exchange and Microsoft 365 accounts, through Outlook on the web and other connection methods
  • used another tool to keep pulling email from Outlook 365 accounts once inside, Infosecurity Magazine reported
  • exploited known software flaws, some first published as early as 2014, including flaws in remote-access and VPN (virtual private network) products
  • injected malicious code into vulnerable websites to show fake login boxes and collect passwords
  • installed VPN software on compromised machines to keep access

What isn’t known: none of the sources name any Canadian victims, and the advisory doesn’t say how many organizations in Canada, if any, were affected.

Who is affected

The advisory names government, critical manufacturing, healthcare and information technology as the main targets, with other victims in education, law enforcement and religious organizations across Southeast Asia, Africa and North America.

More practically, the methods are not specific to large targets. Any organization is exposed if it has:

  • Microsoft 365 or Exchange accounts without multi-factor authentication
  • an older on-premises Exchange server or VPN appliance that hasn’t been updated
  • a public website or web application that hasn’t been patched in a while

What to do now

If you run an organization

These steps come from the advisory’s own mitigations.

  1. Require multi-factor authentication (MFA) on every account, starting with email, VPN and admin accounts. Use the strongest option you can, such as an authenticator app or hardware key.
  2. Check your Microsoft 365 sign-in logs for repeated failed logins across many accounts, sign-ins at odd hours, and logins from two distant places in a short time. The advisory specifically calls out “impossible travel” logons.
  3. Review apps connected to your Microsoft 365 tenant (your organization’s Microsoft 365 account) and remove any that can read mail or files and that you don’t recognize.
  4. Update software and firmware promptly, especially VPNs, firewalls, Exchange servers and web applications. Replace anything that no longer gets security updates.
  5. Turn off services and ports you don’t use, such as remote access and file sharing that face the internet.
  6. Keep offline backups that can’t be changed or deleted from your main systems, and test that you can restore from them.

If you find signs of compromise, the Cyber Centre accepts incident reports through My Cyber Portal or at [email protected].

If you’re a staff member

Use a unique password for your work email, accept MFA when it’s offered, and be cautious with login pages that appear unexpectedly on websites you use.

What this means for organizations in BC and Alberta

For organizations in British Columbia and Alberta that use Microsoft 365, the email-focused parts of this advisory apply directly, whatever your size or sector.

If an attacker reads a mailbox, that can become a privacy breach, because mailboxes usually hold personal information.

  • Organizations covered by PIPEDA (the Personal Information Protection and Electronic Documents Act, Canada’s federal private-sector privacy law): you must report to the Office of the Privacy Commissioner of Canada and notify affected people as soon as feasible when a breach creates a real risk of significant harm.
  • Alberta private organizations (Alberta PIPA, the Personal Information Protection Act): the same “real risk of significant harm” test applies. You must notify Alberta’s Office of the Information and Privacy Commissioner and affected individuals without unreasonable delay.
  • BC private organizations (BC PIPA): there is currently no mandatory breach notification requirement, but BC’s Office of the Information and Privacy Commissioner recommends notifying voluntarily.

How happier IT helps

We can review your sign-in settings, MFA coverage and connected apps as part of Microsoft 365 security, and keep watching for unusual sign-ins afterwards through our managed security services. If you’re not sure where you stand, our free IT assessment is a calm place to start.

Sources

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.