The FBI and NSA jointly announced that Russia has systematically breached the security of home and small business routers since 2024.
See also: FBI warns of rise in cyberattacks on accounting firms

Federal agencies revealed on April 7 that a unit of the Russian military intelligence agency, the GRU group known as APT28 or Fancy Bear, has compromised home and small business routers to steal credentials, identification tokens and sensitive communications. The agencies have taken the unusual step of remotely resetting thousands of affected devices in the U.S. under a court order, but officials warn that without action from the router owners, the problem is far from solved.
See also: iOS 26.4.2: Fixes vulnerability that allowed the FBI to read Signal messages

Affected routers no longer receive security updates and must be replaced. The specific model cited by the FBI was originally released in 2007, although the UK's National Cyber Security Centre indicates that other TP-Link models were also targeted. Since none of these models are now receiving firmware updates, they remain vulnerable to further attacks.
It is important for any router to enable automatic firmware updates and change the default administrator username and password. Unless remote access is specifically required, it is recommended to disable the remote management feature in the administrator settings.
See also: FBI Disrupts APT28's DNS Hijacking Network

The FBI also recommends that remote workers use VPNs when accessing sensitive data.
