Back to Headlines
Technology
Apr 08, 2026

UK warns Russian-linked hackers are exploiting consumer routers for espionage, prompting US ban on foreign-made devices

AI Summary
The UK’s National Cyber Security Centre has alerted the public that Russian‑linked groups, likely APT28/Fancy Bear, are compromising widely used home routers to harvest credentials, hijack DNS and move laterally across networks. The warning coincides with a US FCC ban on foreign‑made consumer routers, underscoring growing geopolitical tensions over cyber‑espionage and the need for timely firmware updates.

The United Kingdom’s cyber‑defence agency has issued a stark warning: Russian‑affiliated hackers are targeting everyday internet routers to conduct espionage operations. By compromising these edge devices, attackers can steal user credentials, redirect traffic to fraudulent sites, and potentially infiltrate other connected gadgets such as smartphones and computers.

According to the National Cyber Security Centre (NCSC), the campaign appears opportunistic, casting a wide net before filtering for high‑value intelligence targets. This mirrors a broader trend where threat actors focus on hardware that bridges users to the cloud, often overlooking the security of routers and network cameras.

Professor Alan Woodward of the University of Surrey emphasized that routers are frequently forgotten, becoming weak points in home and small‑business networks. "If a router is compromised, attackers can reroute users to fake banking sites, establish persistence on the network, and probe connected devices for further vulnerabilities," he explained.

The NCSC attributes the activity to the notorious group APT28, also known as Fancy Bear, which is almost certainly linked to Russian intelligence services. APT28 previously orchestrated high‑profile attacks, including the 2015 breach of the German parliament that exposed confidential emails and legislators' schedules.

In a parallel move, the U.S. Federal Communications Commission has prohibited the sale of all consumer‑grade routers manufactured outside the United States, citing "unacceptable risks to national security." The FCC warned that foreign‑made routers have been exploited to facilitate espionage, disrupt networks, and steal intellectual property. While most routers are produced in China or Taiwan, exceptions like Elon Musk’s Texas‑made Starlink devices are unaffected.

Privacy specialists caution that a blanket ban will not resolve existing vulnerabilities, especially for legacy routers that no longer receive security patches. Woodward urged small businesses and individuals to keep firmware up to date and monitor network activity for anomalies.

The article also revisits the 2016 Bangladesh central bank heist, where hackers siphoned $80 million by exploiting cheap, second‑hand routers that were exposed to the internet. Investigators believe a North Korean state‑linked group was behind that attack, illustrating how compromised routers can serve as gateways to critical financial systems.

Overall, the NCSC’s alert underscores a growing geopolitical cyber‑threat landscape, where state‑sponsored actors leverage everyday hardware to gather intelligence and disrupt adversaries.