Tuesday, April 7, 2026
12 C
New York

Russia-Linked Hackers Hijack Routers to Steal Passwords, UK Says

Share

Russian government-linked hackers are compromising popular internet routers to steal passwords for email accounts and other online services, the U.K.’s National Cyber Security Centre has warned.

The hackers, a group known as APT28, are associated with Russia’s GRU military intelligence agency, according to research published Tuesday by the U.K.

British cyber officials said they have observed the alleged Russian intruders targeting routers manufactured by companies such as MikroTik and TP-Link. Attackers obtain access to the routers and modify their settings so that they redirect outgoing internet traffic through servers that they control. MikroTik and TP-Link didn’t immediately respond to requests for comment.

Such attacks put victims at risk of credential theft, data manipulation and broader compromise, according to the alert, which also published guidance on how to mitigate the risks of an intrusion.

Paul Chichester, the center’s director of operations, said the malicious activity demonstrated that vulnerabilities in commonly used routers could be leveraged by sophisticated hostile actors.

Lumen Technologies’ Black Lotus Labs also published research on Tuesday on APT28’s router-hijacking campaign

The researchers said they had identified thousands of potential victims from at least 120 countries communicating with the hackers’ infrastructure. “These operations primarily targeted government agencies — including ministries of foreign affairs, law enforcement and third-party email providers,” the researchers said in a report reviewed by Bloomberg News.

The vulnerability of internet routers to attack has become a focus of increasing concern internationally.

Last month, the U.S. Federal Communications Commission banned the sale of new foreign-made consumer-grade internet routers, saying that they constituted a “supply-chain vulnerability” and could pose “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.”

Top photo: A person uses a laptop computer with illuminated English and Russian Cyrillic character keys. Bloomberg.

Copyright 2026 Bloomberg.

newsletter

Want to stay up to date?

Get the latest insurance news
sent straight to your inbox.

Admin
Adminhttp://safefirepro.com
Michael J. Anderson is a U.S.-based fire safety enthusiast and writer who focuses on making fire protection knowledge simple and accessible. With a strong background in researching fire codes, emergency response planning, and safety equipment, he creates content that bridges the gap between technical standards and everyday understanding.

Table of contents

Latest Articles

Read More