
The FBI and the NSA jointly disclosed that Russia had been systematically compromised security of home and small office routers at least since 2024.
They’ve obtained a court order to allow remote resets of thousands of affected devices in the US, but if yours is one of them, it needs to be replaced urgently…
CNET reports.
Federal agencies, including the FBI and NSA, revealed on April 7 that a unit of Russia’s military intelligence agency, the GRU group known as APT28 or Fancy Bear, has been systematically compromising home and small office routers since at least 2024, using access to intercept credentials, authentication tokens and sensitive communications. The agency took the unusual step of remotely resetting thousands of US devices affected by the court order, but officials warn that individual router owners are far from solving the problem without taking action.
However, the agencies say the affected routers are no longer receiving security updates and should be replaced.
The good news is that it’s average 9-5Mac it is unlikely that the reader is using one of the affected routers because they are older. The specific model cited by the FBI was first launched in 2007, although the UK’s National Cyber Security Center says other TP-Link models were targeted. These include:
- TP-Link TL-WR841N
- TP-Link LTE Wireless N Router MR6400
- TP-Link Wireless Dual Band Gigabit Router Archer C5
- TP-Link Wireless Dual Band Gigabit Router Archer C7
- TP-Link Wireless Dual Band Gigabit Router WDR3600
- TP-Link Wireless Dual Band Gigabit Router WDR4300
- TP-Link Wireless Dual Band Router WDR3500
- TP-Link Wireless Lite N Router WR740N
- TP-Link Wireless Lite N Router WR740N/WR741ND
- TP-Link Wireless Lite N Router WR749N
- TP-Link Wireless N 3G/4G Router MR3420
- TP-Link Wireless N Access Point WA801ND
- TP-Link Wireless N Access Point WA901ND
- TP-Link Wireless N Gigabit Router WR1043ND
- TP-Link Wireless N Gigabit Router WR1045ND
- TP-Link Wireless N Router WR840N
- TP-Link Wireless N Router WR841HP
- TP-Link Wireless N Router WR841N
- TP-Link Wireless N Router WR841N/WR841ND
- TP-Link Wireless N Router WR842N
- TP-Link Wireless N Router WR842ND
- TP-Link Wireless N Router WR845N
- TP-Link Wireless N Router WR941ND
- TP-Link Wireless N Router WR945N
Since none of these models have received firmware updates yet, they remain vulnerable to future attacks and should be replaced.
It’s important for any router to make sure you enable automatic firmware updates and change the default admin username and password. If you do not need to access your router remotely, it is also recommended to disable the remote control feature in the admin settings.
Finally, the FBI specifically recommends remote workers Use a VPN when accessing sensitive information.
The author of the photo Jackson Sophat about Open it
FTC: We use automatic affiliate links that generate income. More.








