Skip to content
Sunday, October 11, 2026
Express News Bulletin

Top stories, at express speed.

Technology

US Moves to Disrupt Hacking Network Linked to China’s Integrity Tech

The United States has announced an effort to disrupt hacking infrastructure run by China's Integrity Tech Group, according to Reuters headlines on October 9, in the latest action…

Share WhatsApp Facebook X LinkedIn Email
Rows of servers in a data centre with blue lighting
Rows of servers in a data centre with blue lighting. CC BY-SA 3.0 via Wikimedia Commons (File:BalticServers data center.jpg), by BalticServers.com

The United States has announced an effort to disrupt hacking infrastructure run by China's Integrity Tech Group, according to Reuters headlines on October 9, in the latest action targeting the private-company layer of state-linked cyber operations. Such disruptions typically combine court-authorised seizures or takedowns of servers and domains with sanctions or indictments intended to raise the cost of rebuilding.

Integrity Tech has been named in prior Western government reporting on intrusion infrastructure, and the pattern of these actions is cumulative: each takedown publishes indicators that defenders worldwide can block, forces the operator to reacquire infrastructure, and creates the attribution record that later measures rely on. The operational effect is real but temporary unless the underlying personnel and funding are also constrained.

Beijing routinely rejects United States attributions of state-linked hacking and characterises American disclosures as politically motivated, while Washington maintains that contractor ecosystems blur the line between commercial security firms and intelligence tasking. Express News Bulletin attributes the disruption and the Integrity Tech link to the United States announcement as reported; the company's and China's responses, when published, belong in the same record.

For ordinary network defenders, the actionable content of these announcements is technical, not diplomatic: the published indicators, vulnerable device classes and patching guidance. Infrastructure built from compromised routers and edge devices, as described in earlier advisories on this ecosystem, is cleaned by updating and rebooting one's own equipment, not by following the geopolitics.

Further detail is expected in the formal advisories that accompany such operations, which usually name the agencies involved, the court authorities used and the period the infrastructure was observed. We will update this report when the full advisory is available to cite precisely.

Allied governments increasingly publish their own parallel advisories during such operations, both to share blocklists quickly and to signal that attribution is collective rather than unilateral. Whether this announcement follows that pattern will be visible within days. Collective attribution does not make any single claim true, but it does tell defenders that several independent collection efforts reached compatible conclusions — the closest this field gets to corroboration the public can inspect.

Recent articles by Express News Bulletin Business & Technology Desk