Summary
- The NCSC published the joint advisory on 8 October 2026. It names Integrity Technology Group and describes AI-enabled tools, large-scale botnets and hands-on exploitation
- The UK agency says Integrity Tech has links to the Chinese government and has enabled malicious China-linked actors to target networks globally. These are assessments mad
- The advisory was co-sealed with international agencies from Australia, Canada, Japan, New Zealand, Spain and the United States, reflecting the geographical spread of the
Britain’s National Cyber Security Centre and international partners have linked a China-based technology company to infrastructure and services used in malicious cyber operations against organisations around the world.
The NCSC published the joint advisory on 8 October 2026. It names Integrity Technology Group and describes AI-enabled tools, large-scale botnets and hands-on exploitation techniques used to compromise networks and obtain sensitive information.
The UK agency says Integrity Tech has links to the Chinese government and has enabled malicious China-linked actors to target networks globally. These are assessments made by participating security authorities, not conclusions from a criminal court.
The advisory was issued jointly with international agencies from Australia, Canada, Japan, New Zealand, Spain and the United States, reflecting the geographical spread of the infrastructure and the threat being investigated.
Integrity Tech had already appeared in a September 2024 public warning, when the NCSC and partners identified it as the operator of a substantial botnet that had been used by the advanced persistent threat group known as Flax Typhoon.
Botnets consist of compromised internet-connected devices that can receive instructions and support malicious activity. Such infrastructure can distribute scanning tasks, conceal the actual operator or route connections through systems owned by unrelated organisations.
As a result, a connection from a compromised appliance does not necessarily identify the actor controlling the operation. Attribution requires the combination of technical artefacts, infrastructure history and other intelligence held by investigators.
The latest disclosure places automated reconnaissance beside active intrusion techniques. Tools that scan internet-facing systems can identify exposed services at scale, while access to an individual target still depends on exploitation conditions and the attacker’s subsequent actions.
Although the advisory refers to artificial intelligence, it does not establish that every stage of an intrusion runs autonomously. Automated scanning, malware infrastructure and direct operator activity can coexist within the same campaign.
The advisory also distinguishes between providing an operational ecosystem and conducting particular attacks. An organisation enabling malicious infrastructure can be significant to an investigation without being publicly identified as the individual operator of each intrusion.
Across UK and European organisations, the immediate technical exposure concerns reachable network devices and services that attackers can discover and compromise. The same equipment can become both a target and part of the infrastructure used against other organisations.
Large-scale campaigns are not limited to one industrial sector, and the NCSC says a breadth of sectors has been targeted globally. However, the public warning does not independently prove compromise at any particular organisation not named in the underlying evidence.
International coordination also reflects the limits of investigations conducted in one jurisdiction. Affected devices, service providers, operational infrastructure and victims may be located in several countries, requiring agencies to compare evidence and publish common indicators.
The reference to covert networks also raises a distinction between an intrusion into an organisation and the abuse of equipment owned by that organisation as an intermediary. Devices recruited into a botnet may help attackers reach unrelated targets, while their owners may not be aware that the equipment is being used in that way.
The NCSC published its statement with a link to a separate joint technical advisory hosted by the FBI. The press statement provides the high-level attribution and risk description, while the accompanying document is intended to supply the indicators and technical detail used for detection and mitigation.
The participating agencies have not publicly established an incident count attributable to the newly described ecosystem, and the advisory should not be read as a census of compromised European organisations.
The NCSC has directed organisations to the mitigation advice accompanying the joint advisory. The latest statement extends earlier warnings about Integrity Tech and covert networks, while individual incident investigations remain necessary to establish the effects on specific systems.





