Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
NewsAI-assisted

Russian Intelligence Hackers Hijack Thousands of Routers in Global Spy Campaign

Russian hacking group Fancy Bear hijacked 18,000 routers globally to steal passwords and bypass 2FA, prompting a major international takedown operation.

Russian Intelligence Hackers Hijack Thousands of Routers in Global Spy Campaign

Global Cyber Espionage Campaign Linked to GRU

A sophisticated hacking operation tied to Russian military intelligence has compromised thousands of home and small business routers across the globe. According to a joint warning issued Tuesday by government authorities and private security researchers, the campaign is designed to intercept internet traffic, harvest passwords, and bypass security protocols to access private accounts.

The group behind the attacks is Fancy Bear (also known as APT 28), an elite unit widely believed to be part of the Russian GSGRU. The group has a long history of high-profile operations, including the 2016 breach of the Democratic National Committee and the 2022 disruption of the satellite provider Viasat.

How the Attack Works: High-Jacking the Gateway

Security researchers from Black Lotus Labs (the research arm of Lumen) and the UK’s National Cyber Security Centre (NCSC) revealed that the hackers targeted unpatched vulnerabilities in routers manufactured by MicroTik and TP-Link.

By exploiting outdated software, the attackers modified device settings to redirect internet requests to hacker-controlled infrastructure. This "man-in-the-middle" tactic allows them to:

A sophisticated hacking operation tied to Russian military intelligence has compromised thousands of home and small business routers across the globe.
Camille Blanchard · The Hacking Post
  • Direct victims to fraudulent "spoof" websites.
  • Steal login credentials and authentication tokens.
  • Access online accounts while bypassing two-factor authentication (2FA).

The NCSC described the campaign as "opportunistic," noting that the attackers cast a wide net across thousands of devices before honing in on specific targets of high intelligence value.

Thousands of Victims in 120 Countries

The scale of the operation is vast. Black Lotus Labs identified at least 18,000 victims in approximately 120 countries. The list of affected entities includes:

  • Government departments and law enforcement agencies.
  • Email service providers.
  • Organizations across North Africa, Central America, and Southeast Asia.

Microsoft, which also tracked the campaign, reported identifying over 200 compromised organizations and 5,000 consumer devices, specifically highlighting the breach of at least three African government entities.

Advertisement

International Response and Takedown

The threat has triggered a coordinated international response. A coalition including the FBI and Lumen has moved to disrupt the botnet and take the hackers' infrastructure offline. While a spokesperson for the FBI did not provide an immediate comment, the agency is expected to formally announce the seizure and takedown of various domains used by the Russian group.

Security experts urge users of MicroTik and TP-Link routers to ensure their devices are updated with the latest firmware to mitigate the risk of exploitation. Many of the hijacked routers had been running vulnerable software for years, leaving them open to remote attacks without the owners' knowledge.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories