Skip to main content

Share story

Security Policy

UK warns Russian hackers are hijacking popular routers to steal credentials

Outlook logo Image: Tom's Hardware
The United Kingdom has issued an alert that Russian state-sponsored hackers are compromising widely used internet routers to steal passwords and redirect traffic for intelligence gathering. APT28, a hacking group linked to Russian military intelligence, is actively targeting routers from manufacturers including MikroTik, TP-Link, and other popular brands found in homes and small businesses, according to UK authorities. The attacks enable credential harvesting from email accounts and other online services accessed through compromised devices. By controlling network gateways, the attackers can intercept unencrypted traffic and redirect users to malicious sites. Router compromises pose significant challenges for detection. Unlike endpoint malware, router infections often persist for months without visible symptoms. Most consumers lack the technical knowledge to check router firmware integrity. The UK alert follows similar warnings from other Western governments about Russian cyber activity targeting critical infrastructure and communications networks. APT28, also known as Fancy Bear, has been linked to numerous high-profile operations including the 2016 Democratic National Committee breach. Security experts recommend that router owners update firmware regularly, change default passwords, and disable remote administration features when not needed. Enterprise networks should implement network segmentation to limit the impact of compromised edge devices. The campaign represents ongoing Russian efforts to establish persistent access to Western communications infrastructure for both intelligence collection and potential future disruptive operations.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Bloomberg, Tom's Hardware and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Products
Security Products

Texas disclosure puts Oracle healthcare breach at nearly 20 million people

Information released by the Texas attorney general puts the scope of last year's cybersecurity breach at Oracle's healthcare unit at nearly 20 million people, Bloomberg reported. The breach compromised personal information belongi...

Security AI
Security AI

AWS reports 89.0% success for Continuum on code security benchmark

AWS says its Continuum security system passed 819 of 920 tasks on CyberGym-E2E within the benchmark's 90-minute limit, achieving an 89.0% success rate. That exceeds the previous public high of 65.9% by 23.1 percentage points. The...

AI Policy
AI Policy

OpenAI opens optional API text watermarking and plans EU rollout

OpenAI opened optional text watermarking for API customers worldwide on October 5 and plans to add invisible watermarks to eligible ChatGPT and Codex output in the European Union over the coming weeks, Unite.ai reported. API water...

Policy Products
Policy Products

CFTC proposes framework for leveraged retail crypto spot trading

The CFTC proposed a federal framework that would let crypto exchanges offer retail customers leveraged and margined spot trading without congressional action, The Block reported. These trades allow customers to take positions usin...

Security AI
Security AI

Google, JPMorgan and government teams fix flaws in AI tool servers

Google, JPMorgan Chase, Weaviate and two government teams have fixed flaws that could let attackers direct AI tool servers toward internal systems, The Next Web reported. Researcher Syed Anas Mohiuddin reported all five vulnerabil...