The National Security Authority of Slovakia (NBÚ) together with international partners has discovered a global spy network that uses common home and office routers to steal confidential data. The attacks are carried out by the APT28 group, which is controlled by Russian military intelligence.
Internet routers, which are in every home and office, have become a key target for a new wave of cyberattacks. According to the NBÚ, hackers from the APT28 group (also known as Fancy Bear or Forest Blizzard) exploit the weak security of these devices to gain access to private correspondence, passwords, and state secrets.
How the spy scheme works
The attackers focus on devices with outdated software or default factory passwords. After gaining access to a router, they use the DNS hijacking tactic — changing settings that allow the user's internet traffic to be redirected through servers controlled by hackers.
This way, hackers can intercept:
logins and passwords for social networks and banking accounts;
two-factor authentication tokens;
emails and browsing history;
in some cases — even encrypted communication.
A coalition of intelligence services from Slovakia, the Czech Republic, Germany, Poland, Canada, Ukraine, and the USA participated in uncovering this network. American law enforcement officers from the FBI have already carried out a successful operation to neutralize part of the infected infrastructure, but the threat to individual users remains relevant.
How to check and protect your router
Cybersecurity experts emphasize: a router is the front door to your digital life, and it should not be left open. The NBÚ recommends taking three simple steps:
Change the default credentials. If you still use the login
adminand passwordadmin(or1234) to access your router settings, you are an easy target. Set a strong password.Update the firmware. Go to the manufacturer's website or the router's control panel and check for updates.
Say goodbye to old devices. If your router is over 5–7 years old and the manufacturer no longer releases updates for it, such a device is critically vulnerable. The best solution is to replace it with a new model.
For businesses and organizations, it is mandatory to use VPN connections for remote employee work to protect corporate systems from possible leaks through home networks.
If you notice strange activity or suspect a hack, the NBÚ asks you to report it to the email address incident@nbu.gov.sk.


