Adversary Intelligence — 2026-07-07
GRU APT28 Steals UK Government Login Credentials via Router Hijacking Campaign Across 120 Countries
BLUFStolen British government credentials likely compel a mandatory edge-device remediation directive within 30 days, as compromised routers offer GRU persistent access for lateral movement into policy-sensitive networks.
The NCSC assessed in April, with high confidence shared by allies, that GRU Unit 26165 (APT28/Fancy Bear) compromised thousands of MikroTik and TP-Link routers worldwide to conduct DNS hijacking and intercept traffic . The Telegraph reported Sunday that stolen material from the campaign included British government login credentials, according to the UK Defence Journal's account of that reporting 1. Research by Lumen's Black Lotus Labs identified at least 18,000 victims across roughly 120 countries, including government departments, law enforcement agencies, and email providers 12. Intelligence and law enforcement services from the US, UK, Ukraine, Poland, Germany, Italy, Canada, and Romania took part in the investigation, and the FBI's Operation Masquerade sent commands to compromised routers on US soil to evict the intrusion and reset settings 1.
AnalysisRouter-based DNS hijacking at this scale
likely accelerates UK and allied remediation of consumer-grade MikroTik and TP-Link fleets over the coming weeks, since these devices remain the softest entry point into government and defense-adjacent networks, and the stolen credentials likely enable lateral movement into systems touching policy deliberations or supplier data. Moderate confidence reflects single-outlet original reporting on the credential theft against a well-corroborated technical picture from Black Lotus Labs and the NCSC's April attribution, which had established the 120-country router-hijacking scope but not confirmed credential loss. The campaign may instead reflect broad opportunistic harvesting rather than deliberate targeting of UK government systems specifically. Confirmation of further compromised departments would push UK cyber authorities toward emergency remediation and mandatory router replacement across government remote-access points; containment at current scope would leave existing firmware-patch guidance sufficient.
3 sources
- Russia has attacked the United Kingdom – again - UK Defence Journal
- UK Faces Renewed Russian Cyber Assault as Hackers Steal Government Login Credentials - The Defense Watch
- APT28 exploit routers to enable DNS hijacking operations - National Cyber Security Centre (NCSC)
View in full brief →