Day Lila

Cybersecurity · Friday, 9 October 2026

01 Briefing what happened

The FBI seizes the web addresses behind two hacking tools it says a Chinese company built, as seven governments warn

Cybersecurity 54 sources

The FBI cut off Microscan and FishHub, tools US officials say Integrity Tech used to scan and break into power, airport and university networks. Agencies in seven countries published how the hackers worked.

7

web addresses the FBI seized to cut off the two tools

Each one now shows an FBI notice naming Flax Typhoon and Integrity Tech. [1]

1,300+

ready-made break-in scripts inside Microscan

They test for known flaws in common software such as WordPress and Jenkins. [1]

20+

organisations whose files sat on one FishHub server

Six of them are universities in Taiwan. [1]

200,000+

hijacked home devices in the company's network the FBI took apart in 2024

Cameras, video recorders and home and office routers, AP reports. [6]

The lead story — what happened

  • The FBI has seized seven web addresses that ran two hacking tools, called Microscan and FishHub, US agencies said on 8 October. [1][7]
  • US officials say both tools belong to Integrity Technology Group, a security company in China with government contracts there. [1][4] The Record reports it was hired by China's Ministry of State Security, the country's spy agency. [2]
  • Microscan searched websites and services for weak spots, using more than 1,300 ready-made break-in scripts. [1][7]
  • It scanned a power company in South Carolina, airports in Japan and Poland, and gas and power companies in Taiwan. [1][6]
  • Court papers say scans led to real break-ins, including at two Taiwanese universities in 2022 and 2023. [4][1] The FBI has not said whether the power company or the airports were broken into. [1]
  • FishHub sent fake emails, then planted more malware to copy files out. [4] The FBI found files from more than 20 organisations on one of its servers, six of them universities in Taiwan. [1]
  • The hackers also guessed passwords on Microsoft email servers and ran a website that let other people read the stolen mail. [7][1]
  • Agencies in the US, Britain, Australia, Canada, Japan, New Zealand and Spain published a joint 58-page warning with the addresses and files defenders can look for. [4][2]
  • The eight flaws the hackers used most were all old and well known, the oldest from 2014 and the newest from 2023. [8][1]
  • The warning tells organisations to switch off services they do not use, install fixes, and ask for a second check at every login. [8][5]
  • This is not the first move against the company: in 2024 the FBI took apart its network of more than 200,000 hijacked cameras and routers. [6][7] The US Treasury put sanctions on it in January 2025. [7]
  • An FBI agent told AP the bureau will watch for the company to rebuild. [6]
  1. 1Bash (Shellshock)2,014
  2. 2ProFTPD file server2,015
  3. 3BIND address server2,015
  4. 4Apache Struts2,016
  5. 5Pulse Secure VPN2,019
  6. 6GitLab2,021
  7. 7ONLYOFFICE2,021
  8. 8Strapi2,023
The year each of the eight flaws the hackers used most got its public number. None is newer than 2023.

Who is involved

  • Integrity Technology Group

    a Beijing security company that US officials say has Chinese government contracts; it built and ran Microscan and FishHub

  • The FBI

    the US federal police; its Cyber Division, led by Brett Leatherman, seized the seven web addresses

  • CISA

    the US cyber-defence agency; it published the warning with the FBI, the NSA and six foreign partners

  • Britain's National Cyber Security Centre

    the UK's cyber-defence agency, one of the partners that signed the warning

How it unfolded

  1. 2010 Cai Jingjing, a well-known Chinese hacker, founds Integrity Tech [2]
  2. 2017 Microscan is in use from this year [2]
  3. Sep 2024 the FBI takes apart the company's network of 200,000+ hijacked devices [6]
  4. Jan 2025 the US Treasury puts sanctions on the company [7]
  5. 8 Oct 2026 seven web addresses seized and a seven-country warning published [1][7]

Where this points

The next test is whether Integrity Tech rebuilds its tools on new web addresses, which the FBI says it will watch for, after a 2024 takedown and two rounds of sanctions did not stop it. [6][7]

What is pushing on the whole day

The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.

AI tools used to break in Building↑

CrowdStrike, a US security company, says one person used AI helpers to break into several South Korean banks within weeks. [12][13] Researchers showed one message to a public AWS chatbot could take over every AI helper in a company's account. [37] A Japanese security firm counted 83 data leaks in Japan from July to early October, against 84 in all of 2025, and says cheap AI tools may be one reason. [9]

Police taking tools and money Building↑

The FBI seized the web addresses behind two hacking tools it links to China. [1] Empire Market's co-founder, jailed for 40 years, agreed to give up more than $100 million in Bitcoin. [33] Agents took back about $31 million in cryptocurrency from the man found guilty of robbing Uranium Finance. [34]

Harmful code in trusted places High→

Cheap Android phones sold as Doogee and Cubot models arrived with ad-fraud software already built in. [26] A release of Tensorlake's code kit carried a worm that steals passwords. [27] Fake download pages sit in 17,610 GitHub projects, some under real developers' accounts. [28]

Cloud data centres knocked out Building↑

A ransomware attack shut part of IDCF Cloud, which serves 495 Japanese companies and local governments. [9] A drone strike stopped Yandex's Sasovo data centre in Russia, which holds tens of thousands of servers. [16] Russian strikes damaged at least six Ukrainian data centres late last month. [17]

The rest of the day

30 more stories on this beat.

Each with its own sources. None of these is a link to the story above.

  1. 02

    Ransomware shuts part of a Japanese cloud

    A ransomware attack, which locks files until a payment is made, shut down IDCF Cloud's East Japan Region 1 early on 7 October, its owner IDC Frontier said. [9] IDC Frontier is part of SoftBank Group and rents out servers and storage in Japanese data centres. [9] It says 495 companies and local governments use the hit service. [9] It has locked every customer out of their control panels in all regions while it checks them. [9]

    Why it matters — The attacker claims it wiped 554,153 backup copies, which the company has not confirmed. [9] Nissui, a big Japanese seafood group, also stopped shipping goods after a break-in at an outside data centre, and nobody has said whether the two are linked. [9]

  2. 03

    One person and AI helpers behind Korean bank break-ins

    CrowdStrike, a US security company, says a 26-year-old in China's Guangdong province was likely behind recent break-ins at South Korean banks. [12] He used ARTEX, a free Chinese tool for testing defences, together with AI models including Anthropic's Claude. [13][12] At least nine Korean banks have reported attacks since late September. [12] Shinhan Bank says about 25,000 customers' details were taken, Yegaram Savings Bank 40,000 and KB Kookmin Bank 119. [12][13]

    Customers whose details each bank says were taken in the break-ins.

    Why it matters — CrowdStrike says AI let one person hit many targets in a short time. [12] South Korean police opened an inquiry into the attacks this week. [12]

  3. 04

    Leaked chats show a gang sending people into law offices

    Thousands of leaked messages from the Silent Ransom Group, a Russia-based extortion gang, show it sent paid recruits it called agents into US law firms to copy files. [10] The FBI warned earlier this year of people posing as IT staff in law offices. [10] In one negotiation the demand climbed from a $100,000 offer through $500,000, $1.5m, $2.25m, $3m and $3.5m to a $6m contract. [10] Chainalysis, a company that traces cryptocurrency, matched wallets in the leak to a $10m-plus payment the gang collected in mid-2026. [11]

    One negotiation in the leaked chats, step by step, in millions of dollars.

    Why it matters — The chats list about 50 targets, mostly law firms, and some have never said they were hit. [10] The gang claims about $200 million in payments, a figure nobody has been able to check. [10][11]

  4. 05

    Oracle Health break-in reached nearly 20 million

    A report from the Texas attorney general puts the people hit by the 2025 break-in at Oracle Health at nearly 20 million, Bloomberg reported. [14] Oracle Health is the medical-records business Oracle got when it bought Cerner in 2022. [14] An attacker used stolen customer logins on an old server between January and April 2025. [14] Earlier filings counted far fewer, such as 2,992,244 people in Texas. [14]

    Why it matters — The stolen records include Social Security numbers, diagnoses, medicines and test results. [14] Oracle has not confirmed the new total, which would make it one of the largest health-data thefts in the US. [14]

  5. 06

    Drone strike stops a big Russian data centre

    A drone strike on 8 October started a fire and stopped Yandex's data centre in Sasovo, about 300km south-east of Moscow. [16][18] Yandex is Russia's biggest search and cloud company, and the site holds tens of thousands of servers and two of its three AI supercomputers. [16][15] Yandex says it cannot yet tell whether the equipment can be restored. [15] Ukraine's president did not name the site, but said Ukraine answers Russian strikes on its data centres in kind. [15]

    Why it matters — Reuters calls it the first major attack on a Russian data hub since the war began. [16] Russian strikes damaged at least six Ukrainian data centres late last month, and one cut home internet for about 100,000 households around Kyiv. [17] Ukraine's foreign minister says Russia is trying to cut the flow of information. [19]

  6. 07

    ASOS hackers hold birth dates and searches

    ASOS, the British online clothes shop, now says hackers took detailed customer profiles, after the criminals sent BBC News a sample. [20] The data includes names, home addresses, phone numbers, dates of birth and what customers searched for on the site. [20] ASOS says the attackers got an employee's login by pretending to be a trusted contact. [22][23] They then used it on outside services ASOS uses. [22] ASOS says no card details or passwords were taken. [22]

    Why it matters — ASOS has about 17 million customers and has not said how many were hit. [24][21] It warns that scam calls and messages pretending to be ASOS are the main risk now. [20]

  7. 08

    Cheap phones arrive with hidden ad-fraud software

    Bitdefender, a security company, found harmful software built into cheap Android phones before they were sold, in a campaign it calls Midnight Mimosa. [26] It ran for about two years on thousands of phones in more than 150 countries, including models sold as Doogee and Cubot. [26] The software clicks on hidden adverts and can turn a phone into a relay for strangers' internet traffic. [26] Nobody knows who changed the phones' software, or when. [26]

    Why it matters — Because it sits inside the phone's own system, owners cannot delete it the usual way. [26] Some owners say makers sent updates that removed it, but no maker has said how it got there. [26]

  8. 09

    Fake think tank in Latin America was run from Russia

    OpenAI, the maker of ChatGPT, says it shut down two campaigns from Russia and Iran that used its tools to plant stories in real news outlets. [25] The Russian one ran a fake Latin American think tank fronted by an invented leader called Mia Clark. [25] The staff it hired in Latin America did not know they worked for a Russian group, OpenAI says. [25] The Iranian one used at least seven fake journalists to place almost 100 articles. [25]

    Why it matters — OpenAI could see who ran the think tank because its operators asked ChatGPT about staff wages and firing. [25] One of the Russian group's fake audio clips led Bolivia's government to deny it was about to cut off water to La Paz. [25]

  9. 10

    Password-stealing worm slips into an AI code kit

    A release of Tensorlake's software kit, downloaded about 12,000 times a week, carried Shai-Hulud, a worm that steals passwords and spreads to other projects, researchers said on 8 October. [27] Tensorlake runs AI programs inside sealed-off boxes. [27] But the poisoned kit ran on the developer's own computer while it installed, outside that box. [27] Socket, a security company, flagged it 11 minutes after it went up, and npm, the main store for this kind of code, removed it. [27]

    Why it matters — Socket advises anyone who installed version 0.5.144 to rebuild the machine from a clean copy. [27] This version can delete a user's files if a stolen key is cancelled first, so the order of the clean-up matters. [27]

  10. 11

    Four US states sue router maker TP-Link

    Florida, Iowa, Montana and Nebraska sued TP-Link Systems, a big maker of home internet routers, on 6 October. [31] They say its adverts overstated how safe its routers are, including a 2025 promise of a 100% safeguard. [31] They also say it hides how much of its work still happens in China. [31] The suits point to TP-Link routers hijacked in Chinese hacking campaigns, Flax Typhoon among them. [31] Texas brought a similar case in February. [31]

    Why it matters — Several of the router models named no longer get security updates. [31] The states want fines, refunds and jury trials. [31]

  11. 12

    17,610 fake GitHub projects push a password thief

    A campaign called FakeGit came back on 4 October and now uses 17,610 projects on GitHub, the site where programmers share code, researchers at Apiiro say. [28] It added more than 13,000 of them in 34 hours. [28] Each page offers a download that installs SmartLoader, which then fetches password-stealing software. [28] At least 700 of the accounts seem to belong to real developers. [28] In July another firm, Island, counted 7,600 such projects. [28]

    Fake GitHub projects in the FakeGit campaign, counted by Island in July and by Apiiro in October.

    Why it matters — Deleting one download does not help, Apiiro says, because the gang points the page at a spare copy. [28] Some of the fake projects pose as add-ons for AI assistants. [28]

  12. 13

    Cisco fixes a dozen critical flaws

    Cisco, which makes much of the equipment inside company networks, released fixes on 7 October for 35 flaws, more than a dozen of them rated critical. [30] Five sit in the software of its Nexus switches, the boxes that link servers in data centres. [29] The worst could let an attacker take full control of a switch, but only if certain optional features are switched on. [29] Cisco found all five itself and knows of no attacks. [29][30]

    Why it matters — Cisco offers a temporary shield for switches that cannot be restarted yet. [29] It also fixed flaws in its Meraki network gear and its licence server. [30]

  13. 14

    Empire Market co-founder gets 40 years

    A US judge sentenced Raheim Hamilton, 30, to 40 years in prison on Monday for running Empire Market, a hidden website for buying drugs and stolen data. [33] More than 4 million sales worth $430 million went through it from 2018 to 2020, most of them drugs. [32][33] Hamilton agreed to give up more than $100 million in Bitcoin and several properties in Virginia. [33] His partner, Thomas Pavey, will be sentenced later this month. [33]

    Why it matters — The site sold stolen logins and hacking tools beside the drugs. [32] It vanished in 2020 with an estimated $30 million of its users' Bitcoin. [33]

  14. 15

    Uranium Finance hacker found guilty

    Jonathan Spalletta, 36, of Maryland, was found guilty of stealing about $53.3 million from Uranium Finance, a cryptocurrency exchange, in April 2021. [34] He used coding mistakes in the exchange's software, and his second raid took almost 90% of its funds, so it shut down. [34] He spent part of it on rare Pokemon and Magic: The Gathering cards. [34] Agents seized the cards and about $31 million in cryptocurrency. [34]

    Why it matters — He faces up to 20 years in prison for money laundering. [34] A crypto investigator, ZachXBT, first linked coins taken out of a mixing service, which blends coins to hide where they came from, to the hacker in 2023. [34]

  15. 16

    Leader of the 764 network pleads guilty

    Prasan Nepal, 21, of North Carolina, pleaded guilty on 8 October to conspiring to sexually exploit children, the US Justice Department said. [35] He led 764, an online network that groomed and blackmailed children into harming themselves and others. [35] He faces 15 to 30 years in prison. [35] His alleged partner is held in Greece and is expected to face trial within six months. [35]

    Why it matters — Prosecutors say the pair abused at least eight children, some as young as 13. [35] Another 764 leader, Kyle Spitze, was sentenced to 77 years in August. [35]

  16. 17

    114 lawmakers ask Google to halt Spirit data deal

    114 members of the US Congress asked Google and Spirit Airlines on 8 October to stop a deal selling Spirit's internal records to Google for $10 million. [36] Spirit, a US budget airline, has shut down, and Google wants the data to train AI. [36] It includes about 100 million emails, 500 million Microsoft Teams messages, and staff pay and tax records. [36] Google says personal details will be left out or removed first by an outside firm. [36]

    Why it matters — The lawmakers wrote that removing names and email addresses does not always make data anonymous. [36] Almost 1,000 Spirit workers in Las Vegas lost their jobs when it closed. [36]

  17. 18

    One message to an AWS chatbot could seize every AI helper

    Researchers at Zenity showed that one message to a public chatbot built on Bedrock AgentCore, part of Amazon's cloud business AWS, could take over every AI helper in the same account and region. [37] The chatbot could be asked to fetch the temporary keys of the machine it ran on. [37] Its default permissions were also far too wide. [37] Zenity reported it in December, and AWS fixed it in February. [37]

    Why it matters — Zenity showed the flaw at SecTor, a security conference in Toronto, this week, and says it has seen no attacks using it. [37] It is now checking whether other cloud companies share the weakness. [37]

  18. 19

    Anthropic offers AI flaw-finding to defenders

    Anthropic, the AI company that makes Claude, launched a programme on 8 October pairing its models with security firms such as CrowdStrike and Palo Alto Networks. [39] The aim is to find and fix weak spots in power, water and other vital systems. [39] It also launched OSS Scanner, free regular scans for open-source projects, the free code many products are built on. [40] Those reports come straight from the AI with no human check, so some may be wrong, Anthropic says. [40]

    Why it matters — Some open-source projects already struggle with a flood of AI-written bug reports. [40] Anthropic says it has offered its models to more than half of US states. [39]

  19. 20

    OpenAI hides a mark in its AI's writing in Europe

    OpenAI will add an invisible mark to text written by ChatGPT and Codex for users in the European Union, to meet the EU's AI Act. [41][43] The mark is a pattern in the words the AI picks, which a detector can spot. [41] In OpenAI's own tests, detection fell from about 92% to 66% when one word in ten was swapped for a similar word, and to 17% when a quarter were. [41] Only approved researchers can use the detector for now. [42]

    How often OpenAI's detector found its own mark in its tests, as more words were swapped.

    Why it matters — OpenAI says a missing mark does not prove a person wrote the text. [41] Anthropic marks its AI's text everywhere, not only in Europe. [43]

  20. 21

    Contest hackers find 45 new flaws in a day

    On the second day of Pwn2Own Ireland, a contest that pays researchers to break into fully updated devices, they used 45 flaws nobody knew about and won $232,500. [38] Samsung's Galaxy S26 phone was broken into three times, and a Sonos speaker in under a minute. [38] Trend Micro's Zero Day Initiative, which runs the contest, gives makers 90 days to fix each flaw before it is published. [38]

    Why it matters — No one signed up to attack Apple's iPhone 17, despite a top prize of $300,000. [38] The last day turns to phones, smart-home kit and printers again. [38]

  21. 22

    Britain and Germany join up against Russian attacks

    Britain and Germany announced a partnership on 8 October to share information and act together against cyberattacks and sabotage, mainly from Russia. [46] It came as Prime Minister Andy Burnham went to Berlin for his first meeting with German Chancellor Friedrich Merz. [46] It builds on the Kensington Treaty on defence and security, which was ratified the same day. [46] The announcement names no agencies and no new money. [46]

    Why it matters — Germany blames Russia for an attempted drone attack at Leipzig airport in August. [46] Britain is also rushing through a law that lets its Home Secretary list groups that act for hostile states. [46]

  22. 23

    Senator says Trump Mobile lacks a key licence

    US Senator Maggie Hassan says Trump Mobile, a phone service that licenses the Trump family name, does not seem to hold the US authorisation needed to sell international calls. [47] It also appears not to have filed a required plan for stopping robocalls, she wrote on 8 October. [47] Her letter follows a hack in which criminals say they took data on 3,615 customers. [47]

    Why it matters — That authorisation asks who owns a phone company, so US officials can check for foreign control. [47] Hassan says a ransomware group claims Trump Mobile told it that it had no team to handle the breach. [47]

  23. 24

    Anyone can now check pictures for Google's AI mark

    Google opened a public website, SynthID.com, where anyone can check an image, video or sound file for SynthID, its hidden AI mark. [44] Before, outsiders had to ask Google's Gemini chatbot. [44] The checker now also reads the marks of partners including OpenAI, Nvidia and Kakao, and soon Apple. [44] Google says Gemini has put the mark on more than 180 billion images and videos. [44]

    Why it matters — The site only answers yes or no, and does not show which part of a picture an AI made. [44] It finds marks only from companies that use SynthID. [44]

  24. 25

    Teams will flag fake voices and faces in calls

    Microsoft says Teams, its video-call and chat app for workplaces, will let approved outside companies scan meetings for faked voices and video. [45] Teams will also warn people when a meeting organiser or guest may be pretending to be someone else. [45] Both features are due worldwide in November. [45] Last month Microsoft said Teams will also blur QR codes that outsiders send. [45]

    Why it matters — Criminal gangs, ransomware gangs among them, have used Teams to contact staff while posing as colleagues or IT help. [45]

  25. 26

    Thousands of AI servers show their insides online

    Researchers at Lava, a data-centre security start-up, found about 2,100 AI servers sharing detailed health readings from their chips on the open internet with no password. [48] The chips, the GPUs that run AI, were worth about $100 million. [48] A flaw in the Nvidia tool that shares the readings, fixed in September, let anyone crash it with enough requests. [48] The servers belonged to about 300 organisations. [48]

    Why it matters — The readings help an attacker map which machines to aim at. [48] 44% of the exposed chips were in the US. [48]

  26. 27

    US agency flags flaws in grid and factory gear

    CISA, the US cyber-defence agency, published warnings on 8 October about flaws in openPDC and openHistorian, free software used by power companies. [52] The maker fixed them, but upgraded systems keep an old setting that leaves one connection open, so operators must change it by hand. [52] No fix is planned for its ready-made Docker copies. [52] CISA also warned that Red Lion's N-Tron 700 switches, used in factories and offices, can be taken over and made to restart again and again. [53]

    Why it matters — Red Lion's fix is firmware version 3.11.1. [53] Red Lion also suggests switching off the switch's web page where it is not needed. [53]

  27. 28

    Russia-linked spies keep sharpening their malware

    ESET, a European security company, says UAC-0099, a spying group aligned with Russia, improved its MATCHBOIL malware steadily for two years. [50] MATCHBOIL is a downloader, a small program that fetches the group's other tools once it is inside. [50] Newer versions hide their code better and check whether they are being watched in a test box. [50] Victims were in Ukrainian transport, factories and energy as recently as June. [50]

    Why it matters — The group has long aimed at Ukraine's government, banks and media. [50] ESET found samples from April 2024, more than a year before Ukraine's own cyber team first described the malware. [50]

  28. 29

    Website certificates to expire after 64 days

    Let's Encrypt, a free service that issues the certificates behind the padlock in web browsers, will cut their life from 90 days to 64 from 10 February 2027. [49] A shorter life means a stolen or wrongly issued certificate is useful for less time. [49] Website owners can test the change from 14 October. [49] A 45-day limit is planned for 2028. [49]

    Why it matters — Sites that renew by hand or on a fixed timer could see their certificates run out without warning. [49] Let's Encrypt is also cutting how long a past check on a website can be reused, from 30 days to 10. [49]

  29. 30

    Watchdogs press for codes quantum computers cannot break

    The US Government Accountability Office, which checks how federal agencies work, said on 6 October that none of the 24 agencies it reviewed has fully prepared for quantum computers. [51] Such computers could one day break the codes that protect most data today. [51] Europol, the EU's police agency, published two reports on 7 October. [51] One warns that data stolen now could be decoded later, once such machines exist. [51]

    Why it matters — Google has said that day could come as soon as 2029. [51] The GAO has made 89 recommendations to 23 agencies. [51]

  30. 31

    Fake crypto wallet add-ons pulled from Firefox

    Socket, a security company, found 16 add-ons for the Firefox web browser that posed as the Rabby and OKX cryptocurrency wallets. [54] When a user typed in a wallet's recovery phrase, the secret words that unlock it, the add-on sent it to the attackers. [54] All 16 had been removed by 5 October. [54] Socket says they continue a wave of similar add-ons it found in August. [54]

    Why it matters — Socket says anyone who typed a real recovery phrase into one should treat the wallet as stolen. [54]

02 Lesson why it matters

The records hackers keep are how they get caught

The FBI, Chainalysis, CrowdStrike and OpenAI each found today's attackers in records the attackers kept themselves.

The twist

Hackers can hide their names and where they live. But a group that pays staff and chases victims has to keep notes, and investigators keep finding those notes.

How it works

  1. A big operation has many people, payments and targets to track
  2. So it writes them down: chats, coin wallets, notes to an AI helper
  3. Those records sit on servers and apps it does not fully control
  4. A leak, a seizure or an open folder brings them out
  5. Investigators match them to victims, money and names

The same force, elsewhere today

Where this chain is also running, in today's other stories.

  • Leaked chats show a gang sending people into law offices

    The gang kept a sales list of victims and paid staff from coin wallets, and after the leak Chainalysis matched those wallets to a payment it already knew about.

  • One person and AI helpers behind Korean bank break-ins

    The attacker left his AI helper's session notes in an open folder on his own server, and they held his Telegram name and home city.

  • Fake think tank in Latin America was run from Russia

    The operators asked ChatGPT about staff wages and firing, and those questions showed OpenAI who really ran the think tank.

  • Uranium Finance hacker found guilty

    A crypto investigator linked coins taken out of a mixing service to the hacker in 2023, years before he was found guilty.

Where you've seen this

Organised crime

account books seized in raids have convicted bosses the police never caught in the act

Company fraud

staff emails kept on the company's own servers become the evidence in court

Doping in sport

a doctor's own coded records and stored blood led investigators to the athletes

The catch

It only works when the records come out. A group that writes little down, or works from a country that will not hand over its servers, stays out of reach, as Integrity Tech's staff in China still are.

And the whole of it

The same records also hold the victims: the law firms on the gang's sales list, the bank customers in the stolen files. Most people on those lists will never see them.

03 Truth what's really going on

What is really going on

The US cannot arrest the staff of Integrity Tech, a Chinese company it says builds hacking tools for groups tied to China's government, because they are in China. [1][6] So it took the web addresses their tools used, after a 2024 takedown and sanctions in 2025, and the FBI says it will watch for the company to rebuild. [6][7]

Why it works on us — An FBI notice on a seized website looks like an ending, so a takedown feels final even while the company behind it keeps working.

Who gains

  • Network defenders at power, health and government bodies — The seven-country warning hands them the addresses, files and eight old flaws to check their own networks for. [8][4]
  • Google — If the Spirit deal goes ahead, it gets about 100 million emails and 500 million Teams messages to train AI, for $10 million. [36]
  • Anthropic — Its free scans and its programme with CrowdStrike, Palo Alto Networks and others put its models inside the security work of more than half of US states. [39][40]
  • Researchers at Pwn2Own — They were paid $232,500 in one day for 45 new flaws, which the makers now have 90 days to fix. [38]

Who pays

  • 495 companies and local governments on IDCF Cloud — Their East Japan services are down, and they are locked out of their control panels while the company checks every region. [9]
  • ASOS customers — Criminals hold their names, addresses, birth dates and searches, which can make scam calls more convincing. [20]
  • Patients in Oracle Health's old Cerner systems — Up to nearly 20 million had Social Security numbers and medical records taken, by the Texas report's count. [14]
  • Former Spirit Airlines staff — Their contracts, timecards, pay and tax records are in the data Google would receive. [36]
  • Owners of cheap Doogee and Cubot phones — Their phones arrived with ad-fraud software they cannot delete the normal way. [26]
  • South Korean bank customers — About 25,000 Shinhan Bank customers and 40,000 at Yegaram Savings Bank had details taken. [12][13]

What nobody knows yet

Open questions from across today’s stories — ours included.

  • 01

    Which of the scanned targets were actually broken into.

    The FBI named a South Carolina power company and airports in Japan and Poland as scanned, but did not say whether any of them were breached. [1]

  • 02

    Who could read the stolen email.

    The warning says the hackers ran a website giving outsiders access to stolen mail, and does not say who those outsiders were. [7]

  • 03

    How big the company's 2024 network of hijacked devices was.

    AP and BleepingComputer say more than 200,000 devices. The Record and The Register say 260,000. [6][1][2][4]

  • 04

    How many ASOS customers were hit.

    ASOS has about 17 million customers and has not given a number. [24][20]

  • 05

    Whether nearly 20 million is the real Oracle Health total.

    The figure comes from a Texas report, via Bloomberg. Oracle has not confirmed it, and state filings so far are far lower. [14]

  • 06

    Whether the Silent Ransom Group really collected about $200 million.

    That is the gang's own figure. Chainalysis confirmed some wallets but not the total, and Crystal Intelligence could not verify it either. [10][11]

  • 07

    Who put the malware into the cheap phones.

    Bitdefender found software signed with a Shenzhen phone maker's certificate, but says it is unclear whether that company was involved. [26]

  • 08

    Whether the IDCF attacker's claims are true, and whether Nissui's outage is linked.

    The attacker says it wiped 554,153 backup copies. IDC Frontier is still investigating and has not said. [9]

  • 09

    Whether Yandex's AI supercomputers were damaged.

    Two of its three sit at the Sasovo site, and Yandex has not said. [15]

04 Hope carry this

Socket, a security company, spotted a password-stealing worm in Tensorlake's code kit 11 minutes after it was published, and the bad version was taken down.

Also true today

  • Agents took back about $31 million in cryptocurrency, plus a collection of rare cards, from the man found guilty of robbing Uranium Finance.
  • Researchers at Pwn2Own Ireland found 45 new flaws in one day and handed them to the makers, who now have 90 days to fix them.
  • Cisco found five serious flaws in its own data-centre switches before any attacker did, and released fixes.
  • AWS closed a hole that let one chatbot message take over every AI helper in an account, months before the researchers who found it showed it in public.

Across the beats