Hacker NewsInternational NewsNewsOther VideosUS NewsVideos

U.S. Treasury Sanctions Beijing Integrity Technology Group for Helping Flax Typhoon Reach American Networks

On January 3, 2025, the Treasury Department’s Office of Foreign Assets Control named Integrity Technology Group, Incorporated, a Beijing cybersecurity company, as a sanctioned party for supporting Flax Typhoon, a Chinese state-sponsored hacking group. The listing freezes any Integrity Tech property that sits under U.S. jurisdiction and forbids American persons from dealing in that property. It is the same legal hammer Treasury uses on ransomware crews and weapons fronts. This time the target sold itself as a security vendor.

Flax Typhoon has been tracked since at least 2021. Public reporting and U.S. government write-ups have tied the cluster to intrusions against organizations in U.S. critical infrastructure. Treasury’s own press release said that between summer 2022 and fall 2023, Flax Typhoon actors used infrastructure tied to Integrity Tech while they broke into victim networks, and that the group routinely sent and received information through that infrastructure. One cited incident involved a California entity in summer 2023.

Staged image of gloved hands at a laptop with a Chinese flag, used to illustrate U.S. sanctions on Integrity Technology Group.

US sanctions Chinese cyber firm linked to Flax Typhoon hacks

The Week After Treasury Was the Victim

The timing is the part of the file that should not be sanded off. On December 30, 2024, Treasury told Congress that Chinese state-sponsored hackers had remotely accessed department workstations and stolen unclassified documents through a compromised BeyondTrust key. That is the department as victim. Four days later, the same department as accuser put a Beijing firm on the SDN list for helping a different Chinese cluster reach American networks.

Those are not the same intrusion set. Mixing them is sloppy. Leaving them in separate silos is also sloppy. Together they describe a procurement world in which U.S. agencies buy remote-support tools from vendors, Chinese operators walk through those tools or through allied infrastructure, and Treasury answers with a sanctions notice because a courtroom in Beijing is not available.

Read the January listing next to the December 2024 BeyondTrust breach of Treasury workstations. One story is a stolen key on an American vendor. The other is a Chinese company accused of lending pipes to Flax Typhoon. Same architecture, opposite desks.

Laptop with United States and China flags used to illustrate the Integrity Tech sanctions and U.S.-China cyber conflict.

What the Designation Actually Does

OFAC designated Integrity Tech under Executive Order 13694, as amended by Executive Order 13757, the cyber sanctions authorities that cover significant malicious cyber-enabled activities against U.S. networks and critical infrastructure. Property and interests in property of the company that are in the United States, or in the possession of U.S. persons, are blocked. Entities owned 50 percent or more by a blocked person are blocked too. U.S. persons may not provide funds, goods, or services to the company.

That is not a fine. It is a cutoff. Banks, cloud providers, and anyone who wants to stay inside the dollar system have to treat Integrity Tech as radioactive. Integrity Tech, in public comments after the listing, called the decision factually baseless. That is the expected answer from a firm that still wants customers. Treasury does not adjudicate press releases. It publishes a name and waits to see whether the name still appears in incident reports.

No individuals were named in the January 3 package. That matters. A company designation is easier to route around with a new letterhead than a package that also lists engineers and executives. Later 2025 actions against other Chinese cyber actors, including people tied to separate clusters around the Treasury and telecom compromises, showed Washington is willing to name humans when the evidence file is thick enough. This particular notice named a company.

Flax Typhoon Is Not a Logo

Western governments have described Flax Typhoon as a Chinese state-sponsored group that lives in routers, cameras, and other edge devices that nobody patches. The preferred on-ramp is not a custom zero-day against a hardened agency laptop. It is a forgotten appliance in a hospital, a university, or a mid-size contractor that happens to sit near something worth stealing. Integrity Tech, in Treasury’s telling, supplied infrastructure that those operators used as a waystation.

If that attribution holds, the firm was a tool. If it does not, Treasury has labeled a private company as an arm of a government and will live with the diplomatic bill. For defenders the practical note is simpler. Assume the techniques attributed to the cluster are still in circulation, logo or no logo. Sanctions do not delete command-and-control nodes. They make it harder to pay the people who run them through a New York correspondent bank.

The AEGIS Alliance has watched this pattern migrate from press release to press release. Sichuan Silence Information Technology was sanctioned in December 2024 over a mass compromise of firewall products. Other Chinese firms have been named in Salt Typhoon telecom cases. In March 2026 a crew calling itself FlamingChina claimed a 10-petabyte theft from a Tianjin supercomputer and tried to sell the haul. Different names. Same market in which “cybersecurity company” can mean a vendor, a cutout, or both.

Vendor Trust Is the Real Target

Third-party software remains the preferred door for anyone who does not want to fight an agency’s own endpoint team. Agencies can harden their laptops and still lose an afternoon to a tool they do not write. That is not an excuse. It is the procurement model. The useful signal is whether Treasury treats vendors as partners with a bad week or as the place where trust should no longer sit unsupervised.

Integrity Tech sold security. Flax Typhoon, Treasury says, used the company’s infrastructure to break things. Sichuan Silence sold security and was accused of breaking firewalls. BeyondTrust sold remote access and became the hallway into Treasury itself. A reader does not need a clearance to see the rhyme. The companies that promise to watch the door keep turning up in the incident report.

U.S. firms that still have Integrity Tech in a vendor spreadsheet now have a compliance problem, not a technical debate. OFAC’s 50 percent rule is unforgiving. So is the secondary risk of dealing with a company that Beijing will describe as a patriotic champion and Washington will describe as a threat to critical infrastructure. Legal departments will do what they always do: dump the contract, keep the email, and hope no one asks when they first learned the name.

What a Sanctions Notice Cannot Do

It cannot patch the routers Flax Typhoon likes. It cannot force a Chinese court to produce an engineer. It cannot rewind the California intrusion from summer 2023. What it can do is tell every bank and cloud account that still touches the dollar that this particular Beijing letterhead is closed. That is a modest tool. It is also one of the few tools a finance ministry has when the alternative is a war of indictments that will never see a defendant.

The AEGIS Alliance will treat the Integrity Tech listing as an open attribution file, not as a victory lap. Readers who want the rest of this stack can stay inside hacker news and the later claim of a 10-petabyte theft from a Chinese supercomputer. One government names a vendor. Another set of operators claims a trophy. The public is left to decide which statement came with evidence.

Until Integrity Tech’s pipes disappear from incident reports, the January 3 notice is a warning label, not a cure. U.S. agencies that still buy security from companies they cannot audit should read their own press release twice.

Jeffrey Childers
Journalist, editor, cybersecurity and computer science expert, social media management, roofing contractor.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Signup for our news and memes newsletters! 

Newsletter Form

Lists
close-link