Independent newsroom

Friday, October 9, 2026

The File

Every claim traces to a primary source. Uncertainty is labeled. Corrections are public.

Justice · Friday, October 9, 2026

U.S. seizes hacking tools a Chinese government contractor used to probe power companies and airports

The File desk · Oct 9, 2026, 10:49 AM UTC

Status

Confirmed as court-authorized seizures. The Justice Department's release, dated Oct. 8, 2026. No one is charged in this release.

  • Confirmed

    The department and the FBI said they seized domains behind two tools, Microscan and FishHub, used by hackers working for Integrity Technology Group.

  • Confirmed

    The release names no defendant and announces no criminal charge.

The Justice Department and the Federal Bureau of Investigation said Thursday they had taken over web domains behind two hacking tools, Microscan and FishHub. Court papers say hackers working for Integrity Technology Group, a company based in China that has Chinese government contracts, used them. Microscan hunted for weak spots in networks. Its targets included a South Carolina power company, airports in Japan and Poland, Taiwanese gas and power companies, and two Taiwanese universities. FishHub used targeted phishing emails to plant malware. About 20 Taiwanese universities were confirmed victims. U.S. officials call the hackers Flax Typhoon. It is the second U.S. disruption of this company's operations in two years. No one is charged.

The seizures were authorized by a court. The affidavit and the seizure warrant were unsealed in the Western District of Pennsylvania. The department says targets of Microscan scanning include a U.S. power company based in South Carolina, a multinational non-governmental organization, Japanese and Polish airports, Taiwanese gas and power companies, and two Taiwanese universities.

FishHub, the department says, delivered malware by spear-phishing. Confirmed activity included about 20 Taiwanese universities. Five of the seized domains helped deliver that malware. Integrity Technology Group also ran a botnet of infected internet-connected devices, a variant of Mirai malware. In September 2024 the department announced a disruption of that botnet, more than 200,000 consumer devices. Thursday's action is the second public disruption of the company's hacking infrastructure, the department says.

The FBI's San Diego and Baltimore offices investigated, with partner agencies that published a cybersecurity advisory. The release number is 26-1155. Do not read this as an indictment. The release charges no one.

What is still unknown or disputed

Primary sources

Every claim in this story is drawn from the documents below. If a fetch failed, that is recorded on the card.

  1. Source 1

    Justice Department and FBI Seize Vulnerability Scanning and Spear Phishing Tools Operated and Used by China-State Sponsored Hackers

    U.S. Department of Justice, Office of Public Affairs · October 8, 2026

    Targets of Microscan vulnerability scanning include a U.S. power company based in South Carolina, a multi-national Non-Governmental Organization, Japanese and Polish airports, Taiwanese critical infrastructure companies in the natural gas and power sectors, and two Taiwanese universities.

    https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-vulnerability-scanning-and-spear-phishing-tools-operated