Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
    • Prolific Chinese Hacking Group Disrupted by DoJ Domain Seizure
    • AI Developers to Strengthen Data Protections Following Inquiries by U.K.’s ICO
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • AI Systems Used by DoD Face Risk of Sabotage by ‘Insiders,’ Sen. Banks Warns
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Cantwell Unveils Framework for ‘Safe and Secure’ Frontier AI
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Privacy Risks From Smart Glasses Prompt Inquiry in Australia
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Security of Test Labs, International Carriers on FCC’s Oct. 29 Agenda
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Senator Queries Trump Mobile Over Robocall, Data Security Issues
    • You have 1 more complimentary views available this month. Log in if you are already a customer
    • Suspected Illegal Robocall Traffic Prompts FCC ‘Show-Cause’ Orders
    • You have 1 more complimentary views available this month. Log in if you are already a customer
  • Articles
  • Articles

    Cybersecurity Policy Report, Prolific Chinese Hacking Group Disrupted by DoJ Domain Seizure, (Oct 8, 2026)

    By Tom Leithauser

    Internet domains used by a Chinese company accused of hacking critical infrastructure have been seized by the Department of Justice and Federal Bureau of Investigation, DoJ announced today.

    DoJ secured a warrant from the U.S. District Court for the We ...

    By Tom Leithauser

    Internet domains used by a Chinese company accused of hacking critical infrastructure have been seized by the Department of Justice and Federal Bureau of Investigation, DoJ announced today.

    DoJ secured a warrant from the U.S. District Court for the Western District of Pennsylvania enabling it to order U.S.-based domain registrars redirect traffic from several domains used by China-based Integrity Technology Group, the department said in a news release.

    DoJ alleged that Integrity Tech was associated with the Flax Typhoon cyber espionage group, which targeted U.S. critical infrastructure, and had developed tools for vulnerability scanning and spear phishing.

    “Integrity Tech created and used a botnet of internet-of-things devices infected with a variant of Mirai malware. Among other things, this botnet facilitated Integrity Tech’s computer vulnerability scanning using Microscan. Integrity Tech developed Microscan to conduct reconnaissance, via the botnet and otherwise, of victim computer networks for vulnerabilities that its clients would later exploit,” DoJ said.

    “A second Integrity Tech tool, FishHub, is alleged to have facilitated the exploitation of computer networks through spear phishing,” it said.

    Integrity Tech’s targets included a U.S. power company based in South Carolina, a multi-national nongovernmental organization, Japanese and Polish airports, and critical infrastructure and universities in Taiwan, according to DoJ.

    “Integrity Technology Group provided China-linked threat actors with capabilities used to conduct widespread vulnerability scanning and, in some cases, intrusions targeting U.S. and foreign critical infrastructure,” said Brett Leatherman, head of the FBI’s Cyber Division.

    “The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity. By exposing and disrupting these enablers, we make it harder for the PRC to target American networks and infrastructure,” Mr. Leatherman said.

    The Treasury Department imposed economic sanctions on Integrity Tech last year (CPR, Jan. 6, 2025).

    In conjunction with DoJ’s seizure of Integrity Tech’s domains, the FBI, Cybersecurity and Infrastructure Security Agency, and National Security Agency, along with cyber defense agencies in Australia, Canada, Japan, New Zealand, Spain, and the United Kingdom, published an advisory to help critical infrastructure organizations identify Integrity Tech’s activities.

    “Integrity Technology Group, a China-based company with links to the Chinese government, enables China-linked threat actors to exploit U.S. and foreign organization networks across multiple sectors using various tools and techniques,” the advisory says.

    “The threat actors targeted victims across multiple U.S. critical infrastructure sectors, including: Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology,” it says. “The actors also targeted victims in U.S. law enforcement, education, and religious organizations, as well as organizations across Southeast Asia, Africa, and North America,” it adds.

    “Chinese government-affiliated actors continue to position themselves within critical infrastructure networks, including operational technology (OT) systems, with the aim of disrupting critical functions at a future time of their choosing,” Chris Butera, CISA’s acting executive assistant director–cybersecurity said in a news release.

    “CISA urges organizations to review this advisory to be aware of the wide range of tactics used by these actors and implement recommended actions and mitigations,” Mr. Butera added. “The advisory underscores the critical role of collaboration between government agencies and the private sector.”

    MainStory: TopStory FederalLegislation InternationalLegislation LitigationEnforcement DataSecurity

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use