Russian Intelligence Hackers Hijack Thousands of Routers in Global Spy Campaign
Russian hacking group Fancy Bear hijacked 18,000 routers globally to steal passwords and bypass 2FA, prompting a major international takedown operation.

Global Cyber Espionage Campaign Linked to GRU
A sophisticated hacking operation tied to Russian military intelligence has compromised thousands of home and small business routers across the globe. According to a joint warning issued Tuesday by government authorities and private security researchers, the campaign is designed to intercept internet traffic, harvest passwords, and bypass security protocols to access private accounts.
The group behind the attacks is Fancy Bear (also known as APT 28), an elite unit widely believed to be part of the Russian GSGRU. The group has a long history of high-profile operations, including the 2016 breach of the Democratic National Committee and the 2022 disruption of the satellite provider Viasat.
How the Attack Works: High-Jacking the Gateway
Security researchers from Black Lotus Labs (the research arm of Lumen) and the UK’s National Cyber Security Centre (NCSC) revealed that the hackers targeted unpatched vulnerabilities in routers manufactured by MicroTik and TP-Link.
By exploiting outdated software, the attackers modified device settings to redirect internet requests to hacker-controlled infrastructure. This "man-in-the-middle" tactic allows them to:
A sophisticated hacking operation tied to Russian military intelligence has compromised thousands of home and small business routers across the globe.
- Direct victims to fraudulent "spoof" websites.
- Steal login credentials and authentication tokens.
- Access online accounts while bypassing two-factor authentication (2FA).
The NCSC described the campaign as "opportunistic," noting that the attackers cast a wide net across thousands of devices before honing in on specific targets of high intelligence value.
Thousands of Victims in 120 Countries
The scale of the operation is vast. Black Lotus Labs identified at least 18,000 victims in approximately 120 countries. The list of affected entities includes:
- Government departments and law enforcement agencies.
- Email service providers.
- Organizations across North Africa, Central America, and Southeast Asia.
Microsoft, which also tracked the campaign, reported identifying over 200 compromised organizations and 5,000 consumer devices, specifically highlighting the breach of at least three African government entities.
International Response and Takedown
The threat has triggered a coordinated international response. A coalition including the FBI and Lumen has moved to disrupt the botnet and take the hackers' infrastructure offline. While a spokesperson for the FBI did not provide an immediate comment, the agency is expected to formally announce the seizure and takedown of various domains used by the Russian group.
Security experts urge users of MicroTik and TP-Link routers to ensure their devices are updated with the latest firmware to mitigate the risk of exploitation. Many of the hijacked routers had been running vulnerable software for years, leaving them open to remote attacks without the owners' knowledge.



