Russia exploiting vulnerable routers in Nigeria, other countries to steal sensitive government information: FBI

The Federal Bureau of Investigation (FBI) has said the Russian General Staff Main Intelligence Directorate (GRU) cyber actors are exploiting vulnerable routers worldwide to intercept and steal sensitive military, government, and critical infrastructure information.
A public service announcement posted on the FBI’s website with alert number: I-040726-PSA, dated April 7, 2026, said the bureau and the U.S. Department of Justice and “recently disrupted a GRU network of compromised small-office home-office (SOHO) routers used to facilitate malicious DNS hijacking operations.”
The FBI said its partners, U.S. National Security Agency (NSA) and international partners from Canada, Czech Republic, Denmark, Estonia, Finland, Germany, Italy, Latvia, Lithuania, Norway, Poland, Portugal, Romania, Slovakia, and Ukraine, made the disclosure to warn the public and encourage network defenders and device owners to take actions to remediate and reduce the attack surface of similar edge devices.
It noted since at least 2024, Russian GRU 85th Main Special Service Center (85th GTsSS) cyber actors — also known as APT28, Fancy Bear, and Forest Blizzard — have been collecting credentials and exploiting vulnerable routers worldwide, including compromising TP-Link routers using CVE-2023-50224.
“The GRU actors changed the devices’ dynamic host configuration protocol (DHCP) / domain name system (DNS) settings to introduce actor-controlled DNS resolvers. Connected devices, including laptops and phones, inherit these modified settings. The actor-controlled infrastructure resolves and captures lookups for all domain names,” the FBI said.
It added that the GRU provides fraudulent DNS answers for specific domains and services — including Microsoft Outlook Web Access — enabling adversary-in-the-middle (AitM) attacks against encrypted traffic if users navigate through a certificate error warning.
According to the bureau, the AitM attacks will allow the actors to see users’ traffic unencrypted.
The FBI noted, “The GRU has harvested passwords, authentication tokens, and sensitive information including emails and web browsing information normally protected by secure socket layer (SSL) and transport layer security (TLS) encryption. The GRU has indiscriminately compromised a wide pool of U.S. and global victims and then filtered down impacted users, especially targeting information related to military, government, and critical infrastructure.”
The FBI and its partners also offered relevant guidance and technical indicators, including NCSC-UK cybersecurity advisory “APT28 exploit routers to enable DNS hijacking operations” on April 7, 2026 and CISA’s Edge Device Security webpage.
The FBI and its partners urge users of SOHO routers to upgrade end-of-support devices, update to latest firmware versions, change default usernames and passwords, disable remote management interfaces from the Internet, and carefully consider certificate warnings in web browsers and email clients.
They further urge oganisations operating remote work to review relevant policies regarding how employees access sensitive data, such as using VPNs and hardened application configurations.
“Additionally, organisations may consider incentivising employees to upgrade outdated personal devices involved in remote access,” the FBI said.
The Bureau, however, warn U.S. citizens and the general public to report to their local FBI field office or file a complaint with the IC3, if they suspect that they have been targeted or compromised by a Russian GRU cyber intrusion.Â
Nigeria has faced a surge in cyber attacks, with over 4,710 weekly threats targeting government and financial data, making it a leading target in Africa. In the past months, there have been breaches relating to data leaks of National Identification Numbers by hackers who sold NIN for as low as N150.Â
We have recently deactivated our website's comment provider in favour of other channels of distribution and commentary. We encourage you to join the conversation on our stories via our Facebook, Twitter and other social media pages.
More from Peoples Gazette

Agriculture
FG tasks ECOWAS on leveraging financing strategies for agroecology
The federal government has urged stakeholders in the agriculture and finance sectors in the West Africa region to leverage financing strategies to enhance agroecology practices

Politics
Katsina youths pledge to deliver over 2 million votes to Atiku
“Katsina State is Atiku’s political base because it is his second home.”

Health
Veterinarians urge renewed commitment to preventing deaths from rabies
Blueblood Veterinary Services has recommended stronger integrated surveillance linking veterinary and human health systems to prevent and eradicate rabies.

NationWide
Road Crashes: FRSC deploys 170 ambulances nationwide for emergency rescue
The Federal Road Safety Corps has deployed more than 170 ambulances nationwide to strengthen emergency response and rescue operations on Nigerian roads.

Opinion
The Black Queen of Hearts: Why Mia Mottley captures the global spirit
For Africa and its diaspora, Mottley now represents something larger than the politics of Barbados.

Showbiz
Kogi moves to harness tourism, digital technology for growth
Kogi is exploring digital technology, artificial intelligence and investment opportunities to transform its tourism sector and harness its vast cultural and historical assets.

Africa
UN chief backs Obasanjo-led AU’s renewed peace efforts in Ethiopia
Mr Guterres endorsed the African Union’s mediation led by Olusegun Obasanjo as escalating fighting in northern Ethiopia raises fears of a broader conflict.

Sport
Super Eagles arrive in Bissau ahead of AFCON 2027 qualifier
Only the group winner will secure an AFCON 2027 qualification ticket, with Tanzania already qualified as a co-host.





