Russian Hackers Are Targeting Vulnerable Routers Worldwide, Cyber Agencies Warn
Cybersecurity agencies from the United States and several allied countries are warning organizations to secure their routers immediately, as Russian state-backed hackers continue to exploit outdated and poorly protected networking devices to access critical infrastructure networks around the world.
The joint advisory, issued by agencies from the U.S., Australia, the UK, Canada, New Zealand, Estonia, Sweden, Denmark, Poland, Finland, France, Czechia, and Italy, says the activity is linked to Center 16 of Russia’s Federal Security Service, commonly known as the FSB. According to the warning, the group has been abusing weak router security for years to steal sensitive information, gather network details, and create long-term access points inside targeted systems.
The campaign is not described as highly complex. Instead, attackers are taking advantage of basic security weaknesses that many organizations still overlook. These include weak or reused passwords, old firmware, exposed services, and default router settings that were never properly changed after installation.
Routers are especially valuable targets because they sit at the edge of a network, often acting as the first gateway between internal systems and the internet. Once compromised, a router can allow hackers to quietly observe traffic, collect configuration files, steal VPN credentials, and map the structure of an organization’s internal network.
The advisory warns that the threat is especially serious for critical sectors, including communications, energy, defense, healthcare, and finance. Rather than immediately launching disruptive attacks, the hackers may use compromised routers to prepare for future espionage, data theft, or more damaging cyber operations.
One of the key concerns is that a single neglected device can become an entry point into a much larger network. Many organizations focus heavily on protecting servers, workstations, and cloud systems, while routers and other network edge devices may receive less attention. Attackers are exploiting that gap.
Cybersecurity officials are urging businesses, government agencies, and infrastructure operators to take immediate action. Recommended steps include updating router firmware, replacing outdated equipment, disabling services that are not needed, removing insecure default settings, and changing factory-set usernames and passwords.
Organizations are also encouraged to use strong, unique passwords and enable multi-factor authentication wherever it is supported. Regular monitoring of routers and network devices is also essential, as suspicious activity on these systems can be an early warning sign of a larger intrusion.
The warning highlights a simple but important lesson: basic router security can play a major role in defending against advanced cyber threats. While nation-state hacking groups may have significant resources, many of their attacks still begin with common weaknesses that can be fixed through routine maintenance and stronger security practices.
For organizations that manage critical systems, securing routers is no longer optional. Keeping firmware current, removing outdated hardware, and actively monitoring network devices may be among the most effective ways to reduce exposure to Russian cyber operations and other global hacking threats.






