The National Cyber Security Centre joined agencies from Australia, Canada, Japan, New Zealand, Spain and the United States in warning that China-linked cyber actors enabled by Integrity Technology Group are combining automated scanning, botnets and manual exploitation to steal sensitive data from organisations worldwide.
The 8 October advisory, co-sealed with the FBI and published on US government channels, urges defenders to hunt for compromises, disable unused services, sanitise web inputs and enforce multifactor authentication. For UK CISOs, it lands during a week of high-profile retail and infrastructure alerts, including guidance for ASOS customers after a separate breach.
What the advisory says about Integrity Technology Group
NCSC said Integrity Tech, a Beijing-based company previously sanctioned by the UK for malicious cyber activity, provides infrastructure that advanced groups use to probe edge devices, exploit vulnerabilities and maintain persistence through VPN software. Last year the agency exposed Integrity Tech as operator of a substantial botnet used by the Flax Typhoon group; the new note describes a wider ecosystem blending hands-on keyboard work with large-scale scanning.
Techniques highlighted include cross-site scripting, password spraying against Microsoft Exchange servers and scripts that exfiltrate mailboxes and credentials. Critical national infrastructure, universities and large corporates are in scope, not just government networks.
Mitigations NCSC wants this weekend
Defenders should prioritise patching edge appliances, reviewing SAML and VPN configurations and checking logs for anomalous authentication after a string of Citrix NetScaler vulnerabilities drew NHS England alerts this week. NCSC’s earlier guidance on covert networks remains relevant because actors hop between compromised SOHO routers and corporate VPNs.
Security teams should also register for NCSC’s Early Warning service if they have not already, giving government analysts a channel to flag malicious IPs touching UK IP space.
Why British boards are on notice
The advisory does not name UK victims, but it arrives as regulators expect directors to treat cyber risk as a board issue. Firms that dismissed Integrity Tech sanctions as geopolitical noise now face concrete TTPs to hunt for in SIEM data.
With AISI separately tightening agent testing after real-world contacts during evaluations, October is a month where both state-linked espionage and experimental AI tooling are forcing UK organisations to redraw perimeter assumptions. The NCSC note is the practical checklist accompanying the geopolitical headline.
Sector checklist
Universities running exposed research databases should verify VPN logs for password-spray patterns, while manufacturers with legacy Exchange servers need urgent patch verification. Retailers already on alert after the ASOS incident should not assume state-linked actors and criminal fraudsters use different playbooks; both hunt for reused passwords.
NCSC recommends disabling unused remote-access services and enforcing phishing-resistant MFA on administrator accounts. Security operations centres can map the advisory’s indicators to existing threat-intelligence feeds rather than building new content from scratch.
Sanctions context
The UK government sanctioned Integrity Technology Group last year alongside another Chinese information-security company for activity against UK networks. The new note ties that policy action to operational tradecraft defenders can hunt for today, rather than leaving sanctions as a diplomatic gesture alone.
