Russian military cyber types have been caught fiddling with the plumbing of the UK internet.
The UK’s National Cyber Security Centre says an elite unit has been breaking into common routers and quietly shunting traffic through attacker-controlled servers.
The NCSC said on Tuesday that Russian state group APT28, tied to military intelligence, has been exploiting vulnerable routers to run domain name system hijacks. That lets the crooks intercept traffic, nick passwords, and grab access tokens from personal web and email services.
The security bods pointed the finger at two networking kit suppliers, TP-Link and MikroTik, as being exposed to the method.
UK National Cyber Security Centre director of operations Paul Chichester said the findings “demonstrate how exploited vulnerabilities in widely used network devices” can be used by sophisticated hackers.
He urged companies and individuals to tighten up, with the NCSC recommending security updates and regular antivirus scans.
The NCSC said the activity was “likely opportunistic in nature”, with attackers spraying the internet first and worrying about the juicy targets later. That wide-net approach makes sense when you want plenty of compromised boxes to hide behind.
Germany has seen the same grubby fingerprints. In a warning released alongside the NCSC’s, Germany’s domestic intelligence agency said it had also been targeted, and the Federal Office for the Protection of the Constitution said it had contacted operators of targeted TP-Link routers last month.
APT28 has form. The NCSC said it is “almost certainly” the GRU, or Russian military intelligence Unit 26165, and it has been linked to hits on the US Democratic National Committee, the German Bundestag and western logistics supporting Ukraine.
It goes by different nicknames, including Forest Blizzard and Fancy Bear.
TP-Link has already been flagged by US experts as a target in major Chinese cyber operations uncovered in 2023 and 2024, the Salt Typhoon and Volt Typhoon campaigns. That history is awkward when your routers keep showing up in other people’s incident reports.
TP-Link’s own site calls the “blame game” a “myth”. “According to publicly available information, Chinese threat actor campaigns, including Volt Typhoon, Salt Typhoon, and Flax Typhoon, have no discernible preference for using TP-Link routers as a vector. These actors have targeted a wide range of routers from several different manufacturers,” the company statement said.
Last month, the US Federal Communications Commission banned new foreign-made consumer-grade internet routers, warning that they posed a supply-chain vulnerability.







