WASHINGTON, Oct. 11, 2026 — The U.S. Justice Department and FBI say they have seized seven internet domains linked to tools used in a China-associated hacking campaign targeting networks in the United States and abroad. The court-authorized operation, announced October 8, disrupted infrastructure supporting the MicroScan vulnerability scanner and FishHub spear-phishing platform.
What federal investigators say
According to the Justice Department, the domains were associated with China-based Integrity Technology Group and activity tracked as Flax Typhoon. Authorities allege the tools were used to identify vulnerable systems, deliver malicious software and, in some instances, gain unauthorized access to networks.
Investigators described scanning or targeting activity involving a South Carolina power company, airports in Japan and Poland, Taiwanese energy infrastructure and universities. A network being targeted or scanned does not necessarily mean it was breached. The government’s allegations and technical findings should not be interpreted as proof that every named organization suffered a successful intrusion.
What the seizure accomplished
MicroScan was described as a tool for identifying security weaknesses, while FishHub supported targeted phishing and access to compromised networks. Taking control of seven domains can interrupt access to the associated infrastructure, but does not establish that the wider hacking operation or all infected systems have been eliminated.
U.S. authorities link the activity to Chinese state-sponsored actors. That attribution is the U.S. government’s assessment; China has disputed American allegations about its involvement in cyberattacks.
Why it matters
The case illustrates how internet-facing devices, scanning platforms and stolen access can expose critical infrastructure and institutions across borders. Organizations should consult official cybersecurity advisories and review their systems for published indicators of compromise rather than assuming the domain seizures have removed every threat.
Sources: U.S. Department of Justice, October 8, 2026; FBI statements and court documents referenced in the announcement; independent technical reporting by BleepingComputer, October 8, 2026. This article describes government allegations where attribution or responsibility has not been independently established.
