The U.S. Treasury imposed sanctions on a China-based cybersecurity company tied to the compromise of firewall products, activity associated with the Flax Typhoon hacking campaign, and attempted ransomware attacks against U.S. victims. Reporting said the company operated infrastructure and services that supported intrusions, with the action aimed at disrupting a broader ecosystem used to access victim networks and enable follow-on malicious operations.
Treasury later expanded its cyber-related sanctions by targeting Funnull Technology, which U.S. officials described as a major facilitator of online fraud and cyber scams that caused more than $200 million in losses. Authorities said the company provided technical infrastructure that helped criminals run scam platforms and conceal their operations, underscoring a broader U.S. effort to use financial sanctions against firms accused of enabling both state-linked intrusions and large-scale cyber-enabled fraud.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
The U.S. Treasury took action against Funnull Technology, describing it as a major facilitator of cyber scams that enabled more than $200 million in victim losses. The sanctions targeted the company's role in providing infrastructure used to support large-scale online fraud operations.
The U.S. Treasury announced sanctions against Integrity Technology Group for its role in compromising firewall products and supporting cyber operations associated with Flax Typhoon, including attempted ransomware attacks. The action publicly linked the company to the broader China-backed intrusion campaign.
Integrity Technology Group, a Beijing-based cybersecurity company, was identified as infrastructure support for the China-linked Flax Typhoon hacking campaign, which compromised firewall products and was tied to attempted ransomware activity. The activity occurred before the U.S. sanctions action and forms the basis for later enforcement.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
techmonitor.ai
Open sourcehome.treasury.gov
Open sourcebleepingcomputer.com
Open sourcehome.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.