BREACH WATCH BRIEF High 🦠 Threat intel

FBI Seizes Domains Used by Chinese Hacking Tools That Compromised Critical Infrastructure

The FBI took down domains hosting MicroScan and FishHub, Chinese tools that scanned for vulnerabilities and delivered malware to critical‑infrastructure targets, including universities. The incident underscores the need for continuous third‑party oversight and audit‑ready evidence of vendor risk management.

SeverityHigh
Type🦠 Threat intel
ConfidenceHigh
ReportedOct 8, 2026
Energy & Utilities Energy & utilities Transportation (airports) Higher‑education institutions Vulnerability Exploit Supply Chain Attack
Check if you use it. This incident came through a third party or the supply chain. If the product or supplier is in your estate or your vendors', start with the questions to ask below.

What happened

The FBI seized seven domains linked to Integrity Technology Group, which provided the MicroScan vulnerability‑scanning platform and the FishHub spear‑phishing tool to Chinese state‑sponsored actors. The tools were used to scan networks, breach at least two Taiwanese universities, and exfiltrate data from more than 20 organizations.

Why it matters for trust and compliance

  • This case illustrates why a continuous control‑assurance program must include ongoing monitoring of third‑party tools and documented due‑diligence to meet audit expectations across frameworks.
  • Continuous monitoring of external services provides defensible evidence for audit readiness.
  • Documented vendor oversight satisfies control objectives that span multiple compliance frameworks.

Who is affected

Energy & utilities Transportation (airports) Higher‑education institutions

Recommended actions

  1. Create an inventory of all third‑party scanning and phishing tools and map them to your risk register.
  2. Deploy continuous monitoring for suspicious domain activity and retain logs for audit trails.
  3. Perform a risk assessment on any tool with privileged network access and remediate identified gaps.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.