-
The FBI seized seven websites tied to two hacking tools called MicroScan and FishHub.
-
U.S. officials say a China-based firm, Integrity Technology Group, ran the tools to scan networks and steal data.
-
A new government notice tells companies how to spot the attack and protect their systems.

The FBI took down seven websites this week. The sites powered two hacking tools used in attacks on power plants, airports and schools. The U.S. Department of Justice announced the seizures on October 8, 2026. Officials linked the tools to a hacking group known as Flax Typhoon.
U.S. authorities say a China-based company called Integrity Technology Group ran the tools. This company holds contracts with the Chinese government. Officials say the firm used the tools to scan networks, find weak spots and break into computer systems. The FBI hopes the seizures will stop the hackers and their clients from using these sites.
Two Tools Worked Together to Scan and Steal
The first tool, called MicroScan, searched websites and online services for security gaps. The Justice Department said the group also used a network of hacked devices infected with a virus called Mirai. This network helped the scanning run faster and wider.
MicroScan held more than 1,300 scripts. These scripts looked for flaws in popular business software, such as Oracle WebLogic, Apache Struts, WordPress and Jenkins. The group also used password-guessing attacks on Microsoft Exchange email servers. This lets them steal emails and login details from targets.
The second tool, FishHub, worked differently. It helped the hackers send fake emails to trick people into clicking bad links. Once inside a network, FishHub delivered more harmful software. That software lets the hackers search for files, control devices from afar and send stolen data back to their own servers.
Officials confirmed that FishHub hit about 20 universities in Taiwan. They also found a separate remote-access tool linked to one of the seized sites. This tool connected hacked networks straight to a server run by Integrity Tech.
In total, the FBI seized the main scanning site, called c0cc.cc, along with five sites used to spread harmful software. Those five sites were 98aicai.com, 98aicode.com, outlook3650.com, youtubecard.com and linkedinns.net. A seventh site, 98aiblog.com, helped the group keep remote access to hacked systems.
The FBI says these tools no longer work through the seized sites. Still, this does not mean every part of the hacking system is gone for good.
Many Groups Were Targeted, but Not All Were Breached
The hackers scanned a wide range of targets. These included a power company in South Carolina, airports in Japan and Poland, and gas and electric firms in Taiwan. They also scanned a large nonprofit group and several universities.
It is important to note one thing. Officials did not say that every scanned target suffered a real break-in. Scanning means the hackers checked a system for weak spots. A break-in means they got inside and took data.
Other reports have also surfaced alleged China-linked data theft claims, including hackers demanding thousands in crypto for a peek at an alleged China data breach. The Justice Department only confirmed actual victims in a smaller number of cases, such as the Taiwanese universities hit by FishHub.
The FBI, along with the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and partners from other countries, released a joint warning. The UK’s National Cyber Security Center also shared details on how the hackers worked. This warning lists the methods the hackers used and gives signs that a system may be hacked.
Groups hit by this campaign include government offices, factories, hospitals, tech firms, schools, police departments and religious groups. The attacks reached organizations across North America, Southeast Asia and Africa.
Experts Tell Companies How to Stay Protected
Security teams now urge companies to act fast. They should check their systems against the signs listed in the new government warning. They should also fix known software flaws right away.
Officials also recommend turning off services that connect to the internet but are not needed. Companies should also turn on multi-factor authentication. This adds an extra step, beyond just a password, before someone can log in.
This is not the first time U.S. authorities have targeted Integrity Tech. In September 2024, officials disrupted a hacking network tied to the same firm. That earlier network controlled more than 200,000 hacked consumer devices. The UK government also placed sanctions on Integrity Tech in December 2025 over its role in harmful cyber activity.
Reuters reported that this latest move marks another step in a longer fight against the group’s hacking tools. BleepingComputer gave a closer look at how the seven sites worked together. The Record also covered how several countries teamed up for this takedown.
Even with the sites down, security agencies warn that the threat has not fully disappeared. They say companies should not assume they are safe just because the domains are gone. Instead, every organization should check its own systems closely and act on any warning signs right away.