Router Security Alert: Russian State-Sponsored Hackers Targeting Network Devices
A joint advisory from cybersecurity agencies, including Australia's ACSC, has highlighted ongoing and persistent malicious cyber activity by Russian state-sponsored actors targeting network infrastructure, particularly routers. These devices are often overlooked in security planning, yet they sit at the edge of a network and can provide attackers with a foothold to intercept traffic, move laterally, or launch further attacks if left unprotected.
The advisory stresses that basic router hygiene remains a critical defence. This includes changing default administrative credentials, applying vendor firmware and security updates promptly, disabling unnecessary remote management features, and ensuring only authorised devices and IP addresses can access router configuration settings. State-sponsored actors are known to exploit weak or outdated router configurations as a low-cost, high-value entry point into otherwise well-defended organisations.
For Australian small and medium businesses, this serves as a reminder that network hardware often runs quietly in the background without regular review. Many SMBs rely on internet service provider-supplied routers or older equipment that may not receive frequent updates, making them attractive targets. Reviewing and hardening router configurations should be treated as a routine part of broader IT security maintenance, not a one-off task.