Futureweb

Security

What the Flax Typhoon seizure release alleges

On October 8, 2026, the Justice Department announced seizures aimed at Microscan and FishHub. It alleges Integrity Technology Group operated them. No verdict is entered.

The short version

Court-authorized access to two tools, Microscan and FishHub, which prosecutors allege Integrity Technology Group used against critical infrastructure and other networks. The documents were unsealed in the Western District of Pennsylvania.

What happened

On October 8, 2026, the Justice Department and the FBI announced court-authorized seizures aimed at two tools they name as Microscan and FishHub. The release says the tools were used to scan and, in some cases, hack U.S. and foreign critical-infrastructure systems and other networks. It says court documents unsealed in the Western District of Pennsylvania allege that people working for Integrity Technology Group, a company based in China with contracts with the Chinese government, operated the tools. The department associates those actors with the name Flax Typhoon. The Associated Press and The Record reported the same announcement. The page filing the release, not a procedure, is Futureweb.

What the release alleges

The allegations, as the release summarizes the court documents, are that Integrity Tech used Microscan to look for vulnerabilities on victim networks, including a U.S. power company in South Carolina, a multinational nongovernmental organization, airports in Japan and Poland, Taiwanese natural-gas and power companies, and Taiwanese universities. It says FishHub was used after a network was already compromised, and that confirmed FishHub victims included about 20 Taiwanese universities. Those are allegations in unsealed documents. They are not a verdict. The desk is Security.

What this page will not reconstruct

The release describes a botnet of internet-of-things devices and says a September 2024 action disrupted a Mirai botnet of more than 200,000 consumer devices. It also says an advisory published with today's seizures contains indicators. This page does not repeat those indicators, does not list the seized domain names, and does not describe how a device was enrolled or how a phish was sent. A reader who wants the domain names has the department's release. An earlier brief on how this desk files an advisory is the advisory is the story.

Why it matters on this desk

The check is a dated seizure announcement, a court, two tool names, and a company the department alleges operated them. Operators of networks in the sectors the release names can see that the department claims those sectors were scanned. They cannot, from this page, pull a block list. The FortiBleed advisory filed yesterday is a different document, about a firewall campaign, and it is what the FortiBleed advisory names.

What the outlets add

The Associated Press reported the same Wednesday announcement: scanning and phishing tools seized, associated with hackers officials tie to the Chinese government, aimed at critical infrastructure including the power industry. The Record reported an international seizure of tools used by the firm behind activity known as Flax Typhoon. Neither outlet is the charging document. Where one of them adds a domain or a step, this page leaves it in the outlet and in the release. What a CVE identifier is, which this seizure is not, is what a CVE identifier is.

What remains an allegation

U.S. Attorney Troy Rivetti, in the release, calls the seizures the department's second disruption of Integrity Tech's operations in as many years. Assistant Attorney General John A. Eisenberg and FBI officials are quoted on the same action. Quotations are the government's account of its own case. Integrity Tech's response is not in the release. Until a court finds facts, the company name, the government contracts, and the victim categories stay inside the word alleged, which is the release's own word. Catalog additions reported the same week, which this release does not list, are the October 8 KEV deadline.

What to watch next

A later indictment that names individual defendants, or a judgment in the Western District of Pennsylvania, would replace the allegation with a court result. A company statement that disputes the contract claim would be a new sentence. Another outlet repeating Flax Typhoon would not. The October 8 release is the record this page has.

What the 2024 line is for

The release uses the September 2024 botnet disruption to say this is the second public technical action against the same infrastructure, and it gives the scale of that earlier botnet as more than 200,000 consumer devices. That number is about 2024. It is not a count of devices seized on October 8. Mixing the two would invent a figure the release does not print for this week. A privacy question about who holds a key is a different brief, on Privacy.

What stays a seizure announcement

What stays specific is an October 8, 2026 announcement of court-authorized seizures in the Western District of Pennsylvania, aimed at Microscan and FishHub, alleged to have been operated by Integrity Technology Group and associated with the name Flax Typhoon. It is not a verdict. It is not a domain block list. The Associated Press and The Record reported the same announcement. The next document that matters is the court's, not a restatement of the headline. The release also says the FBI San Diego and Baltimore field offices are investigating, with prosecutors from the Western District of Pennsylvania and the National Security Division. Those office names locate the case. They do not identify a defendant beyond the company the documents allege. A reader who wants the affidavit and the seizure warrant can use the links the department printed under the release. This page does not summarize those filings into a method. The allegation stands on the record until the court itself says otherwise.

Sources

The reports this brief is filing. Futureweb did not republish them.

  1. U.S. Department of Justice, Flax Typhoon seizures (October 8, 2026)
  2. Associated Press, FBI seizure of China-linked tools
  3. The Record, Flax Typhoon tool seizure

Questions

What did the Justice Department announce on October 8, 2026 about Flax Typhoon?

Court-authorized seizures meant to cut off two tools, Microscan and FishHub, which the department alleges were operated by Integrity Technology Group and used against critical infrastructure and other networks.

Which court does the October 8 release say unsealed the Flax Typhoon documents?

The Western District of Pennsylvania. The release says the seizures are alleged in those court documents, not that a trial has produced a verdict.

Whom does the Justice Department associate with the name Flax Typhoon in this release?

Actors it associates with Integrity Technology Group, a company it says is based in China and has contracts with the Chinese government. Those are the release's allegations.

What earlier Integrity Tech disruption does the October 8 release mention?

A September 2024 court-authorized disruption of a Mirai botnet the department says included more than 200,000 consumer devices. The release calls today's action the second public disruption of that infrastructure.

Does this page list the domains the FBI seized?

No. The release names them. This page files the seizure, the two tool names, the court, and the allegation. It does not reprint the domain list or describe how the tools were used.