BREACH WATCH BRIEF High 📋 Threat intel

International Coalition Seizes Chinese State‑Backed Hacking Tools Used in Flax Typhoon Campaign

Law‑enforcement agencies dismantled Microscan and FishHub, two offensive tools created by Integrity Tech and used to scan and phish critical‑infrastructure entities worldwide. The takedown highlights the need for continuous third‑party risk monitoring to satisfy audit and compliance requirements.

SeverityHigh
Type📋 Threat intel
ConfidenceHigh
ReportedOct 8, 2026
Energy & Utilities Energy & utilities Telecommunications Aviation Higher‑education Media Vulnerability Exploit

What happened

A multinational coalition of cybersecurity agencies seized the domains and infrastructure supporting Microscan and FishHub, tools built by Integrity Technology Group for vulnerability scanning and phishing. The tools have been employed since 2017 against power utilities, airports, universities, telecoms and media organizations, enabling long‑term, covert access to target networks.

Why it matters for trust and compliance

  • This incident underscores the importance of a continuous control‑assurance program that tracks, assesses, and evidences the security posture of any external tooling used within your environment.
  • Provides a concrete case for strengthening third‑party risk monitoring and evidence collection.
  • Supports audit readiness by documenting vendor oversight and control‑mapping across frameworks.

Who is affected

Energy & utilities Telecommunications Aviation Higher‑education Media

Recommended actions

  1. Create an inventory of all external scanning and phishing tools and map them to your risk register.
  2. Perform security reviews and continuous monitoring of each third‑party tool.
  3. Document findings in a control‑assurance platform to generate real‑time audit evidence.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.