The US Department of Justice and FBI have moved to disrupt cyber tools that American authorities attribute to activity associated with Flax Typhoon, which they link to China-based Integrity Technology Group. The court-authorized operation included the seizure of seven internet domains and targeted tools allegedly used to scan vulnerabilities and gain access to networks in the United States and abroad.
What Did the FBI Disrupt?

On October 8, the US Department of Justice announced court-authorized seizures involving domains allegedly used by cyber actors associated with Integrity Technology Group.
The operation targeted two tools: Microscan, used to scan systems and identify potential vulnerabilities, and FishHub, which the FBI says supported phishing and attempts to gain access to targeted networks.
Phishing is a technique in which attackers use deceptive messages, websites or communications to persuade victims to reveal information, open malicious files or provide access to their systems.
US authorities say disabling the infrastructure is intended to make continued operations more difficult. The seizure does not, however, establish that every targeted network is secure or that the operators cannot build replacement infrastructure.
What Is Flax Typhoon?
Flax Typhoon is a name used in cybersecurity reporting for a group of activity that US authorities associate with China.
According to the Justice Department, actors associated with Integrity Technology Group used the infrastructure to scan networks and, in some cases, conduct unauthorized intrusions. The FBI says the company has contracts with the Chinese government.
These are allegations made by US authorities and should not be treated as a judicial finding establishing responsibility for every individual incident.
For network defenders, the operational concern is the reported use of vulnerability scanning, reconnaissance and tools designed to obtain access to internal systems.
Why Critical Infrastructure Matters
Cyberattacks against critical infrastructure can have consequences far beyond the theft of corporate data.
Depending on the systems involved, intrusions may threaten:
- Energy: utility networks and operational management systems.
- Transportation: airports, communications and logistics services.
- Education and research: universities and networks holding research data.
- Government: systems that process information and deliver public services.
- Businesses: network equipment, user accounts and confidential information.
The Associated Press reported that activity associated with the tools involved targets including an American energy company, airports in Japan and Poland, Taiwanese universities and other organizations.
That does not mean all those organizations suffered the same type of damage. The targets, confirmed intrusions and resulting impact must be assessed individually.
A Campaign That Predates 2026
The latest operation is not the first US effort against infrastructure associated with Integrity Technology Group.
In September 2024, the Justice Department announced the disruption of a botnet linked to the company that involved more than 200,000 compromised devices in the United States and elsewhere.
A botnet is a network of infected or compromised devices controlled by an operator. Devices can include routers, cameras and video recorders whose owners may not realize they have been compromised.
Such networks can help conceal the source of malicious activity, scan targets or support other cyber operations.
The renewed action illustrates a persistent challenge: disrupting one part of a network does not guarantee that the wider operation has been eliminated. Operators may attempt to rebuild through new domains, servers or compromised devices.
What Organizations Can Do
For companies and institutions responsible for critical systems, the operation reinforces the need for layered cybersecurity defenses.
Practical steps include:
- Patch network equipment and disable services that are not needed.
- Restrict internet exposure, particularly for administrative interfaces and remote-management tools.
- Require multifactor authentication for administrative accounts and critical systems.
- Monitor unusual network traffic, including repeated scanning and unauthorized login attempts.
- Segment networks so that one compromised device does not provide a path into the entire infrastructure.
- Review published indicators of compromise from the FBI and its partners.
The cybersecurity advisory published alongside the operation is intended to help network defenders identify activity associated with the group.
Beijing Rejects the Allegations
The Chinese Embassy in Washington rejected the accusations, saying China opposes hacking and what it described as politically motivated disinformation.
Integrity Technology Group had not publicly responded to a request for comment in Reuters’ reporting.
The allegations about the company’s links to the activity therefore remain claims made by US authorities, while the Chinese side has rejected the accusations at the political level.
What Happens Next?
US authorities and their partners are expected to continue monitoring the infrastructure and looking for signs that the tools are being rebuilt.
For network administrators, an immediate priority is to check systems against the technical indicators published in the cybersecurity advisory.
The operation does not eliminate every threat associated with state-linked hacking groups. It may, however, disrupt a portion of their capabilities and increase the cost of continuing their operations.
The seizure of seven domains illustrates how law enforcement agencies are increasingly targeting not only cyberattacks themselves, but also the infrastructure that makes them possible.
The harder task begins after disruption: identifying exposed systems, closing vulnerabilities and preventing operators from returning through new infrastructure.
For companies, universities and public services, cybersecurity is not merely about protecting data. It is also about maintaining the services people depend on every day.