U.S. Agencies Warn Russian State Hackers Are Targeting Weak Routers
U.S. agencies say Russian FSB-linked actors are exploiting exposed routers and legacy network protocols across critical infrastructure sectors.
Federal cybersecurity agencies are warning U.S. organizations that Russian state-sponsored actors continue to exploit poorly configured and vulnerable routers across critical infrastructure. The joint advisory released July 13, 2026, does not announce a new nationwide breach. It describes an ongoing campaign and urges network defenders to close weaknesses that can expose credentials, network layouts and access paths.
The guidance was issued by the National Security Agency, Cybersecurity and Infrastructure Security Agency, FBI, Defense Department Cyber Crime Center and international partners. It attributes the activity to Russiaโs Federal Security Service, or FSB, Center 16. Cybersecurity companies use overlapping names for related activity, including Berserk Bear, Energetic Bear, Dragonfly, Ghost Blizzard and Static Tundra. The advisory cautions that those industry labels do not necessarily represent exact one-to-one government attributions.
How the router attacks work
The agencies say the actors scan internet-connected devices for active Simple Network Management Protocol services that still accept common or default โcommunity strings.โ SNMP is used to monitor and manage network equipment, but older versions can rely on weak, shared credentials and lack the authentication and encryption available in SNMPv3.
The actors can use SNMP commands and other weaknesses to copy router configuration files and transfer them to infrastructure they control. Those files may contain network details, credentials, management settings and information about connected systems. The advisory also identifies exploitation of Cisco Smart Install and known vulnerabilities in Cisco devices, while making clear that the campaign is broader than one manufacturer or product.
An earlier FBI public service announcement dated August 20, 2025 said investigators had detected the collection of configuration files from thousands of networking devices associated with U.S. entities. That warning also said some vulnerable devices were modified to enable unauthorized access and reconnaissance inside victim networks. The earlier FBI notice provides context for the July 2026 advisory but is not itself a new July breach announcement.
Who is at risk
The July advisory identifies communications, the Defense Industrial Base, energy, financial services, government services and facilities, and health care and public health as critical-infrastructure sectors most at risk. Government organizations at the state and local levels are specifically included. The warning does not establish that every organization in those sectors has been compromised.
What organizations should do now
The agencies recommend disabling Cisco Smart Install, replacing SNMPv1 and SNMPv2 with SNMPv3 where devices and operational requirements support it, and using strong authentication and encryption. Organizations that must retain older protocols should change default community strings, limit access and avoid read-write permissions where possible.
Network defenders should also use access-control lists and firewalls to restrict management traffic, monitor SNMP requests and device logs, investigate unusual local accounts or configuration changes, patch firmware and replace equipment that has reached end of life. The advisory encourages U.S. federal, state, local, tribal and territorial governments and critical-infrastructure organizations to consider CISAโs no-cost Cyber Hygiene services.
Organizations that suspect compromise should preserve router, configuration and logging information and report suspicious activity to CISA or the FBI. The guidance is a strong federal and international recommendation, not a new legal requirement for every organization. The next developments to watch are any additional indicators of compromise, victim disclosures, incident reports or follow-up guidance from federal agencies, vendors or affected organizations.
Sources
- NSA, CISA, FBI and partners joint cybersecurity advisory
- National Security Agency July 13, 2026 announcement
- FBI IC3 August 20, 2025 public service announcement
- Cisco Talos Static Tundra analysis
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.