FBI Seizes Domains Linked to Chinese ‘Flax Typhoon’ Campaign Targeting Power, Airports, and Universities
U.S. authorities confiscated seven domains that a Beijing‑based company used to host intrusion tools for large‑scale scanning, spear‑phishing, and data theft. The activity hit utilities, airports, universities and NGOs, highlighting the need for continuous third‑party monitoring and audit‑ready evidence of control enforcement.
ADTP Breach Watch· October 9, 2026· DataBreachToday
SeverityHigh
Type🎣 Threat intel
ConfidenceHigh
ReportedOct 9, 2026
Energy & UtilitiesEnergy & utilitiesAviationHigher‑educationNon‑profit / NGOsPhishing
What happened
The FBI seized seven domains that hosted the MicroScan and FishHub tools operated by Integrity Technology Group, a Chinese firm with government contracts. The tools were used to scan internet‑facing systems, deliver spear‑phishing malware, and steal files from victims including a South Carolina power utility, airports in Japan and Poland, Taiwanese energy firms, universities, and an NGO.
Why it matters for trust and compliance
The incident underscores the importance of a continuous third‑party risk‑management program that monitors external threat‑intel, validates vendor sanctions status, and retains evidentiary logs to satisfy audit requirements across multiple frameworks.
Continuous monitoring of threat‑intel feeds provides real‑time evidence of malicious infrastructure exposure.
Documented vendor oversight (sanctions checks, domain blocking) creates a defensible audit trail for compliance reviews.
Who is affected
Energy & utilitiesAviationHigher‑educationNon‑profit / NGOs
Recommended actions
Integrate reputable threat‑intel feeds into DNS filtering and SIEM to block known malicious domains.
Update third‑party risk registers to flag sanctions‑listed entities and verify supply‑chain partners are not using seized infrastructure.
Collect and retain logs of inbound connections to the seized domains for audit and incident‑response evidence.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.