Morning Overview

The NSA is telling Americans to lock down home routers after Russia hijacked 5,000 of them

The unremarkable box blinking in a hallway or closet has become a target of Russian military intelligence, and federal agencies want Americans to treat it that way. In a coordinated advisory, the National Security Agency and FBI, working with the Department of Justice, warned that Russian state hackers had compromised thousands of ordinary consumer routers, using them as quiet footholds to intercept internet traffic and steal login credentials. The government’s message to households is blunt: update the device, change its passwords, and shut down the remote-access features that made the intrusion possible.

A campaign run out of Russian military intelligence

The warning ties the activity to a specific unit rather than a vague foreign threat. The operation has been attributed to GRU Military Unit 26165, a division of Russian military intelligence that cybersecurity researchers track under names including APT28, Fancy Bear, and Forest Blizzard. As the federal public service announcement laid out, the group had been quietly hijacking home and small-office routers and turning them into infrastructure for espionage.

Attribution to a named military unit matters because it reframes what looks like petty device tampering as a state intelligence operation. The routers were not the ultimate prize. They were staging points, compromised hardware that let the attackers position themselves between users and the services those users were trying to reach.

The 5,000 devices at the center of the warning

The advisory drew on findings that put a number on the damage. Investigators identified more than 200 organizations and roughly 5,000 consumer devices caught up in the campaign, with the hackers rerouting internet traffic through fraudulent login pages built to harvest passwords for services such as Microsoft Outlook. The broader footprint was larger still: at its December 2025 peak, tens of thousands of routers across more than 100 countries were reportedly feeding data to servers under the group’s control.

Those figures illustrate why a home router is an appealing target. It sits at the edge of every home network, sees all the traffic flowing in and out, and is rarely inspected or updated by its owner. Compromising it grants a vantage point that is both powerful and easy to overlook, which is precisely what makes a mass campaign like this feasible.

An old flaw in a best-selling budget router

The technical entry point was not some exotic zero-day but a known, unpatched weakness. The attackers exploited a vulnerability cataloged as CVE-2023-50224, a flaw in the TP-Link WR841N, one of the best-selling inexpensive routers in the world. The identifier itself signals that the underlying weakness had been documented years earlier, meaning the devices falling victim were running outdated firmware that left a long-published hole open.

That detail is the practical heart of the story. The campaign succeeded not because the hackers cracked cutting-edge defenses but because millions of cheap routers sit untouched for years, never updated after the day they were plugged in. A widely sold budget device that owners set and forget is a natural mass target, and the reliance on an old flaw is exactly why the government’s remedy centers on updating rather than replacing.

The steps federal officials are urging

The advisory pairs its warning with concrete instructions, and they are deliberately mundane. Officials urged owners of small-office and home routers to install the latest firmware, change default usernames and passwords, and disable remote management interfaces that expose the device to the open internet. Devices that have reached the end of their support life, meaning the manufacturer no longer issues security fixes, should be replaced outright, as reporting on the guidance stressed.

None of those measures is glamorous, and that is the point. Disabling remote management closes the door the attackers walked through, changing default credentials strips away an easy guess, and applying firmware patches seals the specific flaw being exploited. The reason such basic hygiene works is that the intrusion depended on basic neglect.

Why home hardware keeps ending up on the front line

The router campaign fits a broader reality of modern security, in which the weakest points are often the cheap, forgotten devices scattered through ordinary homes rather than the hardened systems of large institutions. State-linked actors have repeatedly gravitated toward this soft underbelly precisely because consumer hardware is numerous, poorly maintained, and easy to weaponize at scale. The same period has brought headlines about advanced computing breakthroughs, from artificial intelligence to experimental quantum processors, even as the most effective real-world attacks still lean on years-old flaws in everyday gear.

That gap between frontier technology and neglected basics is the lesson threaded through the advisory. A government warning aimed at home routers is an acknowledgment that national-security exposure now runs through consumer electronics. The defense on offer is not sophisticated, but it depends on households actually taking the unglamorous steps that unpatched, set-and-forget devices have long invited attackers to exploit.

This article was produced with the assistance of AI and reviewed by the Morning Overview editorial team.



More from Morning Overview