IC Technology & Surveillance — 2026-05-13

FBI Remotely Resets Thousands of Compromised TP-Link Home Routers in Court-Authorized Operation

The Justice Department confirmed in court filings that FBI Boston remotely reset DNS settings on thousands of compromised TP-Link SOHO routers in at least 23 states under court authorization on April 7, redirecting traffic away from GRU-controlled resolvers without affecting router functionality or collecting user data. FBI Boston Special Agent in Charge Ted E. Docks named the effort "Operation Masquerade" and stated that GRU Military Unit 26165, tracked as APT28 or Fancy Bear, had used the hijacked devices to steal credentials, authentication tokens, and sensitive communications from military, government, and critical infrastructure workers. The FBI, NSA, and 15 international partner agencies issued a joint advisory directing owners of the affected TP-Link models to replace them, as the devices are past end-of-support and no longer receive firmware updates.

Analysis
GRU Unit 26165 built its collection architecture around end-of-life civilian routing infrastructure as a durable, low-signature platform against military, government, and critical infrastructure targets, not a staging ground for disruption. The court-authorized DNS remediation sets a precedent for FBI modification of privately owned devices that civil liberties and security stakeholders will contest. It addressed only the hijacking vector; the underlying hardware remains unpatched. Credential collection likely understates the network's purpose: it more plausibly served as a residential proxy mesh for anonymizing GRU offensive operations, with credential theft as incidental yield. The unit has a documented pattern of rebuilding after Western disruptions, and with the remediated fraction undisclosed and a large uncontacted end-of-support pool remaining, reconstitution is probable.
3 sources
  1. The FBI just remotely reset thousands of home and small office routers - TechRadar
  2. The FBI may have reset your wireless router remotely; if so, you should replace it - 9to5Mac
  3. Russian GRU Exploiting Vulnerable Routers to Steal Sensitive Information - FBI Internet Crime Complaint Center

View in full brief →

UNCLASSIFIED // OPEN SOURCE