NEWSAR
Multi-perspective news intelligence
SRCThe Guardian - World News
LANGEN
LEANCenter-Left
WORDS581
ENT8
WED · 2026-04-08 · 11:20 GMTBRIEF NSR-2026-0408-58449
News/Britons warned about Russian hackers targeting internet rout…
NSR-2026-0408-58449News Report·EN·National Security

Britons warned about Russian hackers targeting internet routers for espionage

The UK's National Cyber Security Centre (NCSC) has warned Britons about Russian hackers targeting commonly used internet routers for espionage. The hackers, likely linked to the APT28 or Fancy Bear group associated with Russian intelligence, are exploiting vulnerabilities in these devices to potentially steal credentials, redirect users to fake websites, and access other devices on home networks.

Aisha DownThe Guardian - World NewsFiled 2026-04-08 · 11:20 GMTLean · Center-LeftRead · 3 min
Britons warned about Russian hackers targeting internet routers for espionage
The Guardian - World NewsFIG 01
Reading time
3min
Word count
581words
Sources cited
3cited
Entities identified
8entities
Quality score
100%
§ 01

Briefing Summary

AI-generated
NEWSAR · AI

The UK's National Cyber Security Centre (NCSC) has warned Britons about Russian hackers targeting commonly used internet routers for espionage. The hackers, likely linked to the APT28 or Fancy Bear group associated with Russian intelligence, are exploiting vulnerabilities in these devices to potentially steal credentials, redirect users to fake websites, and access other devices on home networks. This opportunistic campaign targets a wide range of victims, filtering for those of intelligence value. Experts emphasize that these "edge devices" are often overlooked and can become weak points in network security. The US has recently banned foreign-made consumer routers due to security risks and potential for espionage.

Confidence 0.90Sources 3Claims 5Entities 8
§ 02

Article analysis

Model · rule-based
Framing
National Security
Technology
Tone
Measured
AI-assessed
CalmNeutralAlarmist
Factuality
0.70 / 1.00
Factual
LowHigh
Sources cited
3
Well sourced
FewMany
§ 03

Key claims

5 extracted
01

The US has banned the sale of consumer-grade internet routers made outside of the country.

factualFederal Communications Commission
Confidence
1.00
02

Russian hackers are exploiting internet routers to harvest information for espionage.

factualUK’s cybersecurity agency
Confidence
0.90
03

Foreign-made routers had been involved in several recent cyberattacks targeting US infrastructure.

factualFederal Communications Commission
Confidence
0.80
04

Attackers could obtain credentials, redirect to fake sites, and access other devices.

factualAlan Woodward, professor at the University of Surrey
Confidence
0.80
05

The group behind the attacks was probably APT28 or Fancy Bear, linked to Russian intelligence.

factualNCSC
Confidence
0.70
§ 04

Full report

3 min read · 581 words
Russian hackers are exploiting commonly sold internet routers to harvest information for espionage purposes, the UK’s cybersecurity agency has said.The hack could allow attackers to obtain users’ credentials, redirect them to fake sites, and potentially access other devices on their home network such as phones and PCs, said Alan Woodward, a professor at the University of Surrey.The National Cyber Security Centre said on Tuesday the operations were “believed to be opportunistic in nature, with the actor targeting a wide pool of victims and then likely filtering down for users of potential intelligence value at each stage of the exploitation chain”.It follows a common pattern of cyber-actors targeting edge devices – hardware such as internet routers or internet-connected security cameras – that act as a bridge between users and the cloud.Woodward said: “It’s not the first time that warnings have come out about routers. The main thing to say is that these so-called edge devices are quite often forgotten about, and they can become a weak point.”If attackers successfully attacked a router, he said, they could “take you to fake sites. You might think you’re going to your bank, but they take you somewhere else.“They can establish themselves on your network, move around your network, and see if the devices on your network – your PC, your phone – have any vulnerabilities.”The group behind the attacks was probably APT28 or Fancy Bear, wrote the NCSC, which was “almost certainly” linked to Russian intelligence services.APT28 was also behind cyber-attacks on the German Parliament in 2015, in which large amounts of data were stolen, including confidential emails and the schedules of German MPs.“We don’t tend to know a lot about them. The suspicion is they’re working on behalf of the Russian state, but no one knows for definite, because often nation-state attacks are done through criminal groups,” said Woodward.The US has recently banned the sale of all consumer-grade internet routers made outside of the country, with the Federal Communications Commission saying they “pose unacceptable risks to the national security of the United States”.“Malicious actors have exploited security gaps in foreign-made routers to attack American households, disrupt networks, enable espionage, and facilitate intellectual property theft,” it said, saying that foreign-made routers had been involved in several recent cyberattacks targeting US infrastructure.As almost all internet routers are made in China or Taiwan, this stands to severely affect a number of US hardware makers. An exception to this is Elon Musk’s Starlink, which manufactures all its devices in Texas.Privacy experts have said this outright ban will not fully address vulnerabilities in existing internet routers, and that a more significant problem may be that internet routers currently in use are at the end of their lives and no longer receiving security updates.Woodward said the NCSC’s warning was an indication that small businesses and individuals should keep their routers updated. “If you’re a small business, you should look out for unusual activities on your network. A lot of routers are just forgotten about.”One of the largest cyberattacks in history, in which hackers stole $80m from Bangladesh’s central bank in 2016, happened because the bank used cheap, secondhand internet routers that were accessible from the broader internet.Hackers were able to access the router, then the core network of the central bank, from there transferring its cash to accounts in the Philippines. It is believed that a state-linked North Korean hacking group was behind the attack.Woodward said: “It’s the classic way that people probe, and it’s almost bound to happen again.”
§ 05

Entities

8 identified
§ 06

Keywords & salience

10 terms
internet routers
1.00
cyber espionage
0.90
russian hackers
0.80
cybersecurity
0.70
apt28
0.60
network vulnerabilities
0.60
fake sites
0.50
edge devices
0.50
data theft
0.40
national security
0.40
§ 07

Topic connections

Interactive graph
No topic relationship data available yet. This graph will appear once topic relationships have been computed.