Last month, the FBI and law enforcement partners across seven countries disclosed a campaign in which hackers linked to a Chinese cybersecurity firm gained sustained access to email systems serving government agencies, law enforcement bodies, healthcare organisations, and religious institutions. The operation highlights a fundamental problem in how we think about email infrastructure security: the gap between perimeter controls and the ability to detect persistent access after the initial compromise.
Access Without Intrusion Detection
What made this campaign notable was not the initial compromise vector—vulnerability scanning and exploitation are routine—but the operational model. Rather than simply exfiltrating data and moving on, the attackers maintained a portal that gave third parties ongoing access to stolen mail. This suggests a deliberate infrastructure design: the threat actors treated the compromised email systems as an asset to be monetised or shared, not merely pillaged.
For infrastructure teams, the implication is stark. A single vulnerability or weak credential can become a persistent entry point if you lack the telemetry to detect unusual access patterns. Most organisations focus on preventing the initial breach; fewer invest in continuous monitoring of email access logs, login anomalies, or unusual data transfers once accounts are already compromised.
The Role of Scanning Infrastructure
The campaign employed custom scanning tools to identify vulnerabilities in target websites. This reconnaissance phase is standard, but it underscores why organisations should treat their external-facing infrastructure as inherently exposed. Web servers, mail gateways, VPNs, and management interfaces are constant targets for automated scanning. The question is not whether your infrastructure will be scanned, but whether you have the logging, alerting, and response procedures to act on suspicious probing before an attacker gains a foothold.
For teams running mail servers or email infrastructure on VPS or dedicated hardware, this means:
- Maintain detailed access logs (SMTP, IMAP, POP3, management panels) with sufficient retention for forensic analysis.
- Monitor for geographic anomalies: login attempts from regions where your users never operate.
- Alert on bulk mail access (unusual volume of messages read or forwarded) rather than waiting for customers to report it.
- Keep patch schedules aggressive; unpatched systems are the default entry point for these campaigns.
The Shareability Problem
The attackers' decision to operate a portal giving multiple parties access to stolen mail suggests a supply-chain element: they were not just stealing for themselves, but running infrastructure to distribute access. This implies the initial compromise was valuable and defensible enough to monetise repeatedly rather than burn immediately.
This matters because it means the threat was not a quick smash-and-grab, but a sustained operational presence. Organisations that discovered the breach early—through credential reuse detection, impossible travel alerts, or unusual mail forwarding rules—would have had months to act. Those without visibility would have discovered the compromise only when a partner or customer reported it.
Email forwarding rules deserve particular attention. An attacker with mailbox access will often create hidden forwarding rules or delegates to ensure they retain access even after the initial entry point is closed. Weekly audits of forwarding rules, delegates, and OAuth app permissions are hygiene that most organisations neglect until they have already been breached.
Infrastructure Posture and Regional Risk
The campaign targeted organisations across Southeast Asia, suggesting adversaries prioritise regions where infrastructure maturity, logging standards, and incident response capabilities may vary. This does not mean organisations in mature markets are safe—it suggests that threat actors allocate effort based on target value and perceived difficulty. Organisations with poor visibility into their own infrastructure are effectively easier targets, regardless of geography.
For those running email services on shared cPanel hosting, VPS, or dedicated infrastructure, the risk is compounded by dependencies. A shared hosting environment compromised at the account level can expose other customers' data if isolation is weak. This is why dedicated infrastructure, or at minimum dedicated mail servers with strong segmentation, is preferable for any organisation handling sensitive communication.
The Monitoring Gap
The core lesson from this campaign is that infrastructure teams often excel at preventing unauthorised access but fail at detecting authorised-looking access by unauthorised actors. Once an attacker has credentials, they blend in. The solution is not stronger passwords alone—it is infrastructure that can answer the question: 'Did this user access this mailbox at this time, from this location, in this manner before.'
Email infrastructure requires the same rigor applied to database access or VPN logs. Centralised logging, time-synchronised across systems, with alerting on deviations from baseline behaviour, is the difference between a quick containment and a breach that spreads across months. If your infrastructure does not give you that visibility, it is worth reconsidering your architecture or provider.
