← Back to news
NCSC (UK)8 Oct 2026 · 2 min read

UK and partners warn of China-linked cyber activity targeting organizations worldwide

The UK’s National Cyber Security Centre (NCSC) and partner agencies have issued a joint warning about cyber activity they attribute to China-linked actors, saying the campaigns have targeted organizat...

The UK’s National Cyber Security Centre (NCSC) and partner agencies have issued a joint warning about cyber activity they attribute to China-linked actors, saying the campaigns have targeted organizations and sensitive information in multiple countries and sectors.

The advisory focuses on Integrity Technology Group, a China-based technology company that the UK and its partners say has supported malicious operations through services, infrastructure and technical capabilities. The NCSC said the activity reflects a broader ecosystem in which commercial firms and individuals may develop tools, obtain infrastructure, host services and assist with network compromises.

According to the agencies, the actors combine automated and hands-on methods to gain access to victim networks. Reported techniques include the use of AI-supported scanning tools, large botnets and manual exploitation of exposed systems. The stated objective is to identify vulnerable devices and services, establish access and obtain confidential data.

The activity described in the advisory overlaps with campaigns tracked by the cybersecurity community under names including Flax Typhoon, Ethereal Panda and Red Juliett. The NCSC previously identified Integrity Technology Group as an operator of a large botnet allegedly used by Flax Typhoon. A botnet is a collection of compromised internet-connected devices controlled remotely for purposes such as scanning, proxying traffic or conducting attacks.

UK authorities sanctioned Integrity Technology Group and another China-based information-security company in 2024 over what the government described as harmful cyber activity affecting the UK and allied countries.

Defensive recommendations

The agencies urged network defenders to review the accompanying technical guidance and strengthen resilience against the reported tactics. Organizations should prioritize the following measures:

  • Patch internet-facing systems promptly and remove unsupported devices from external exposure.
  • Review authentication logs and administrative activity for suspicious access, particularly on remote services.
  • Use multi-factor authentication and apply least-privilege controls for privileged accounts.
  • Segment networks and monitor for unusual connections between devices and administrative systems.
  • Maintain tested incident-response procedures and ensure security teams can rapidly investigate alerts.

The advisory was co-signed by agencies in Australia, Canada, Japan, New Zealand, Spain and the United States. The NCSC said organizations of all sizes should assess their exposure to the techniques described and incorporate the recommended mitigations into their security programs.

Share this article:TwitterLinkedIn