Full Breakdown
Russian GRU Hijacks Home Routers Across 23 U.S. States
6/6/2026, 9:29:45 AM
DNS Hijacking of SOHO Routers
Russia’s military intelligence (GRU) unit APT28—also known as Fancy Bear or Forest Blizzard—conducted a DNS-hijacking operation that compromised small-office/home-office (SOHO) routers in 23 U.S. states. Exploiting unpatched firmware and default passwords, the actors redirected DNS queries through Russian-controlled servers and harvested credentials. Federal agents disrupted the campaign in April via a court order.
Espionage Campaign Background
APT28 has previously been linked to the 2016 DNC breach and NATO attacks. The FBI notes the router campaign has been active since at least 2024, reflecting a broader trend of nation-state actors weaponizing consumer-grade hardware for persistent surveillance.
Impact and Scale
Microsoft’s threat-intelligence team reported more than 200 organizations and roughly 5,000 consumer devices compromised. The FBI described “thousands of devices” across the 23 states. Although the operation primarily targeted enterprise routers, several affected models are also sold for residential use.
Official U.S. and U.K. Responses
The NSA and FBI issued advisories urging firmware updates, password changes, and router replacement. Britain’s National Cyber Security Centre (NCSC) listed 23 TP-Link models as vulnerable and noted TP-Link’s release of security updates for select legacy devices. TP-Link’s spokesperson advised users to upgrade to newer hardware when feasible.
Security Critique of Legacy Routers
Security researchers warn that many affected routers have not received firmware updates for years, leaving “the door to your network unlocked.” Default credentials and lack of maintenance expose both corporate and home networks to large-scale interception.
Conflicting Model Listings
The FBI singled out the TP-Link TL-WR841N model, while the NCSC enumerated 23 TP-Link models and cautioned the list may be incomplete. This discrepancy underscores uncertainty about the full set of vulnerable devices.
Verbatim Quotes
- “For nation-state actors like Forest Blizzard, DNS hijacking enables persistent, passive visibility and reconnaissance at scale,” — Microsoft Threat Intelligence report
- “While these products are outside our standard maintenance lifecycle, TP-Link has developed security updates for select legacy models where technically feasible,” — NCSC spokesperson
- “The longer you carry on doing that, the greater the risk,” — Rik Ferguson, vice president of security intelligence, Forescout
- “There is a big trend of exploiting routers these days, and that goes both for the consumer and enterprise or corporate routers,” — Daniel Dos Santos, vice president of research, Forescout
Recommendations for Users
The NSA’s best-practice guide advises immediate firmware updates, changing default passwords, and replacing obsolete routers with devices that receive regular patches. Users should verify model vulnerability via TP-Link’s advisory and consider upgrading to supported hardware.
