The Justice Department and FBI announced on Oct. 8 that they had seized seven internet domains used by Chinese state-linked hackers to target critical infrastructure and other computer networks in the United States and overseas.
The seizures targeted two hacking tools allegedly operated by cyber actors working for Integrity Technology Group, a Beijing-based cybersecurity company with Chinese regime contracts.
The tools were used to identify security weaknesses, gain unauthorized access to computer networks, and steal information, according to the Justice Department.
In a joint cybersecurity advisory released the same day, U.S. and allied agencies warned that Chinese regime-linked hackers enabled by Integrity Tech had combined automated scanning, large networks of compromised devices, and targeted intrusions to steal sensitive information from organizations worldwide, including U.S. critical infrastructure operators.
A federal magistrate judge in Pennsylvania approved the seizure warrant on Oct. 6, authorizing the domains to be redirected to FBI-controlled servers.
The Justice Department has not announced criminal charges against Integrity Tech or identified individual defendants in connection with the seizures.
The operation marks the second public U.S. disruption of Integrity Tech’s hacking infrastructure in two years.
In September 2024, the FBI dismantled a network of more than 200,000 infected internet-connected devices, including home routers and cameras, that investigators said were used to conduct cyber operations.
However, a newly unsealed FBI affidavit indicates that tools linked to Integrity Tech remained accessible afterward.
Investigators found a server hosting one hacking tool in March 2026 and confirmed that a login page for another was still accessible in September.
“The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity,” said Brett Leatherman, assistant director of the FBI’s Cyber Division, referring to the People’s Republic of China.
“By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure.”
US Power Company, Foreign Airports Targeted
According to the affidavit, one hacking tool, called Microscan, searched computer networks for weaknesses that hackers could later exploit.
Investigators identified scanning activity involving a South Carolina power company, airports in Japan and Poland, a multinational nonprofit organization, and Taiwanese companies operating in the natural gas and electricity industries.
Scanning does not necessarily mean hackers gained access to a network. The court filings do not establish that the power company, airports, or energy companies were successfully breached.
However, investigators said two Taiwanese universities were successfully hacked after their networks had been scanned.
A second tool, FishHub, was used in targeted phishing operations designed to trick victims into opening malicious content.
After an initial breach, it could deliver additional software that allowed hackers to control computers remotely, search for files, and send stolen information to servers under their control.
The Justice Department said approximately 20 Taiwanese universities were confirmed victims of FishHub activity.
Five of the seized domains were used to deliver the malicious software.
Chinese Regime Contractor
Integrity Tech was sanctioned by the U.S. Treasury Department in January 2025 over its role in cyber operations attributed to Chinese state-sponsored hackers.
At the time, the department said the company had ties to China’s Ministry of State Security, the country’s principal civilian intelligence agency, and provided services to state-security and public-security bureaus.
The department said hackers working for Integrity Tech operated at the Chinese regime’s direction.
The Oct. 8 advisory describes Integrity Tech as a profit-making company whose employees acquire or develop hacking tools for use and sale, provide infrastructure supporting cyberattacks, and compromise networks worldwide.
The agencies said those services contribute to a larger Chinese cyber ecosystem that seeks to steal sensitive information from victims around the world.
Integrity Tech is publicly traded on the Shanghai Stock Exchange under stock code 688244.
In a January 2025 disclosure, the company rejected earlier U.S. allegations, saying they lacked a factual basis. It maintained that it operated legally and had no subsidiaries, business operations, or assets in the United States.
The Epoch Times contacted Integrity Tech, the FBI, and the Justice Department for comment but received no responses before publication.
Asked about the seizures at an Oct. 9 press briefing, Chinese Foreign Ministry spokesperson Mao Ning said Beijing opposed hacking and rejected what she described as politically motivated misinformation.
She accused Washington of double standards and political manipulation but did not directly address the allegations against Integrity Tech.
The United Kingdom also sanctioned Integrity Tech in December 2025 over its alleged involvement in cyber operations targeting British public-sector systems.
Agencies Warn of Worldwide Data Theft
The joint advisory, issued by the FBI, National Security Agency, Cybersecurity and Infrastructure Security Agency, and authorities from six other countries, identified U.S. targets across government services, critical manufacturing, health care, and information technology.
The hackers also targeted American law-enforcement agencies, educational institutions, and religious organizations, along with entities in Southeast Asia, Africa, and elsewhere in North America.
The advisory warned that hackers used a combination of mass scanning and targeted attacks to enter computer networks, steal account credentials, maintain unauthorized access, and remove sensitive files and emails.
Some of the malicious software was disguised as legitimate Windows programs.
Other tools exploited weaknesses in Microsoft email services or enabled attackers to maintain remote access while making their activity harder to detect.
The FBI identified victims of email theft among government agencies, law-enforcement organizations, health care systems, and religious institutions in Southeast Asia.
In some instances, access to the stolen information was restricted to internet addresses in Xiamen, China.
Investigators also discovered a custom online application maintained by the hackers that allowed third parties to retrieve stolen emails from specific accounts, according to the advisory.
The agencies urged government bodies and critical infrastructure operators to search their networks for evidence of compromise, promptly fix known security weaknesses, disable unnecessary services, and strengthen account protections.

