Cyber Security Protection

Russia’s Military Hackers Hijacked Home & Office Routers Across 23 States — Is Yours One of Them?

June 8, 2026 · 4 min read
A hooded figure seen from behind facing a monitor with code, illustrating state-sponsored cyber attack

A unit of Russia’s military intelligence agency (the GRU group known as APT28 / Fancy Bear / Forest Blizzard — the same group behind the 2016 DNC hack) has been quietly compromising small-office/home-office (SOHO) routers across 23 U.S. states. The FBI disrupted the operation in April under court order, but the underlying vulnerabilities — outdated firmware and unchanged default passwords — are still sitting on thousands of devices waiting to be exploited again. Microsoft tied the campaign to more than 200 organizations and 5,000 consumer devices.

This was a DNS hijacking operation: the attackers changed the routers’ DNS settings so all internet traffic passing through the device got silently redirected through Russian-controlled servers. That gave them passive, persistent visibility into traffic and the ability to harvest credentials at scale. The router sits in the most privileged position on your network — every packet you send goes through it — which is exactly why nation-state actors keep going after them.

Why this matters for your business

The FBI specifically called out the TP-Link TL-WR841N, a Wi-Fi 4 router originally released in 2007. The UK’s National Cyber Security Centre published a broader list of 23 TP-Link models known to have been targeted (and warned the list is likely not exhaustive). TP-Link has confirmed every affected model is past End-of-Life — meaning no more security updates, ever.

If one of these devices is sitting in a closet at your office, the front door of your network is effectively unlocked. Every day it stays plugged in, the risk grows.

Affected routers

  • TP-Link LTE Wireless N Router [MR6400]
  • TP-Link Wireless Dual Band Gigabit Router [Archer C5, Archer C7, WDR3600, WDR4300]
  • TP-Link Wireless Dual Band Router [WDR3500]
  • TP-Link Wireless Lite N Router [WR740N, WR740N/WR741ND, WR749N]
  • TP-Link Wireless N 3G/4G Router [MR3420]
  • TP-Link Wireless N Access Point [WA801ND, WA901ND]
  • TP-Link Wireless N Gigabit Router [WR1043ND, WR1045ND]
  • TP-Link Wireless N Router [WR840N, WR841HP, WR841N, WR841N/WR841ND, WR842N, WR842ND, WR845N, WR941ND, WR945N]

If you’re running any of these in a business setting, treat it as compromised until proven otherwise. Replace the hardware and rotate any credentials that may have crossed that network — email, VPN, RDP, banking, anything sensitive.

Five steps everyone should take right now

  1. Replace any End-of-Life router. If your router stopped getting firmware updates, no amount of tweaking will keep it safe.
  2. Update firmware regularly on any router still receiving support — enable automatic updates if the option exists.
  3. Change default usernames and passwords. Default credentials are the single most common way attackers get in. Make the admin password long and random.
  4. Disable remote management unless you specifically need it. This is one of the primary ways attackers reach into a router from the internet.
  5. Reboot routers, computers, and phones at least weekly. Per the NSA: regular reboots help flush implants that live only in memory.

Running one of these in your business? We can help.

If your office is still running a consumer TP-Link (or any other End-of-Life router) for business traffic, Adaptive IT can replace it with enterprise-grade Ubiquiti UniFi equipment — managed switches, access points, and security gateways that get continuous firmware updates, give us central visibility into your network, and are built for business use, not a teenager’s bedroom in 2007.

If you suspect your network may have been touched by this campaign, we can also come in and investigate the damage: DNS log review, credential exposure assessment, lateral-movement checks, and cleanup of any persistence the attackers left behind. The longer you wait, the more time the attackers have to use whatever they harvested.

This is the kind of nation-state-grade attack where waiting and hoping is the most expensive option. Contact us for assistance and we’ll get a network audit on the books this week.

Source: Russia’s Military Hackers Targeted Home Routers Across 23 States. Here’s What to Do (Yahoo Tech / CNET).

Adaptive IT

← What Does a Virtual CIO Actually Do? A… Hurricane Season IT Preparedness Guide for Florida Businesses →
← Back to Blog