Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 114+ sources across the spectrum — sources linked so you can verify it yourself.
FBI and Justice Department seize phishing and scanning tools tied to Chinese hacking group Flax Typhoon

The FBI has seized two hacking tools that officials say were used by a Chinese government-linked group to scan, phish and break into critical infrastructure targets in the United States and abroad. The FBI and Justice Department announced the seizure Wednesday, Oct. 7.
The tools are called "Microscan" and "FishHub." Officials said the operation has left them inoperable.
What the tools were used against
The hackers used the tools to scan for vulnerable systems, phish for access and then break in. Targets included an unnamed U.S. power company, airports in Japan and Poland, Taiwanese universities, a multinational nongovernmental organization and Taiwanese critical infrastructure companies.
The power industry, academia and critical infrastructure were all in the crosshairs, according to the FBI and Justice Department.
The campaign is known in the private sector as Flax Typhoon. The FBI says the group's actual identity is a Chinese information security company called Integrity Technology Group, and that the company is closely associated with the Chinese government. The tools were operated by Integrity Technology Group, officials said.
A second round against the same operation
This is not the first strike on Flax Typhoon. In September 2024, the FBI announced it had disrupted a botnet tied to the group that had infected more than 200,000 consumer devices. Those included cameras, video recorders and home and office routers.
That botnet was used to facilitate cyber crimes, including theft of sensitive information from victims' networks.
The Justice Department and FBI describe the latest action as the newest in a string of law enforcement efforts in recent years against the same broad hacking campaign. Two years on, the group's operators were still running scanning and phishing infrastructure aimed at power companies and airports.
What the FBI says it is trying to do
Jason Bilnoski, deputy assistant director of the FBI's Cyber Division, said the goal is to strip capability from the attackers. "We aim to remove the capability from the threat actors. We target their infrastructure, their money, and their tools," he told The Associated Press.
Bilnoski called the hacking operation "indiscriminate and reckless."
Officials from the FBI and Justice Department said the seizure was a blow to the hacking operation. Tools can be rebuilt, and a state-aligned operator with a corporate front has the resources to try.
Brett Lally, a supervisory special agent in the FBI's San Diego office, said the department will keep watching for signs that the company is rebuilding its infrastructure.
"It'll be interesting to see what this round of disruption actions have in terms of their ability to operate as a company in China," Lally said.
The targets here are not abstract. A power company, airports and critical infrastructure firms are the kinds of systems where intrusions can turn from data theft into physical disruption. The FBI describes the group's operations as "disruptive," not just a spying effort.
The seizure also shows how the U.S. is fighting this kind of threat. Agents are not just naming suspects. They are going after the servers and software that make the campaign work, along with, in Bilnoski's words, the money behind it.
That approach has limits. Disrupting tools does not put anyone in a courtroom, and the announcement as described names a company in China, not individuals in U.S. custody.
Whether Integrity Technology Group can restore its capability, or shift to new tools, is now the open question. Lally's comment suggests the FBI intends to find out, and the next test will be whether the group's activity against U.S. infrastructure drops or simply resurfaces under a new name.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.